[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4663-1] node-lodash security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -----------------------------------------------------------------------
Debian LTS Advisory DLA-4663-1              debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Utkarsh Gupta
July 02, 2026                               https://wiki.debian.org/LTS
- -----------------------------------------------------------------------

Package        : node-lodash
Version        : 4.17.21+dfsg+~cs8.31.173-1+deb11u1
CVE ID         : CVE-2025-13465 CVE-2026-2950 CVE-2026-4800
Debian Bug     : 1126265

Several vulnerabilities were discovered in node-lodash, a Node.js
module providing utility functions for common programming tasks.

CVE-2025-13465

    Prototype pollution in the _.unset and _.omit functions. A
    crafted property path could be used to delete properties from
    built-in prototypes (such as Object.prototype), leading to
    availability and integrity issues.

CVE-2026-2950

    An incomplete fix for CVE-2025-13465. The initial guard only
    handled string key members and the literal "constructor.prototype"
    sequence, so it could be bypassed using array-wrapped path
    segments (for example [['constructor'], ['keys']]), via
    constructor static methods, or from primitive roots, again allowing
    deletion of properties on shared built-in prototypes.

CVE-2026-4800

    Code injection in the _.template function. An incomplete fix for
    CVE-2021-23337: the "variable" option was validated but the
    "imports" option key names were not. Untrusted input passed as
    imports key names could inject default-parameter expressions that
    execute arbitrary code at template compilation time via the same
    Function() constructor sink.

For Debian 11 bullseye, this problem has been fixed in version
4.17.21+dfsg+~cs8.31.173-1+deb11u1.

We recommend that you upgrade your node-lodash packages.

For the detailed security status of node-lodash please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/node-lodash

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpFkjUACgkQgj6WdgbD
S5Y75RAA6UU8qCYcHXO3yINyAEkLrQ1ZfCwESeGJX/4ChH5TRwp+jh///6UUapY3
ct3tJRZHq0qpDhjHn/G00x5P9uToN9J6/MCwPKq9dnHEb22xAHatSUmEmpl589i3
KIG2VxT9j4USBfoLjRrU8AozOniTYL49GXsO4n9AlTVDMhZ/UUKI/AZTP9X2UGt3
e/CUaN1tlfE200UXbcKfqAI5+IL3LC4cN56AHCeYBrmeB1T62CEz7oGPbqNWyayb
BzqYqNKxBODExSbHXWEhegA4eB/vSJGTAEYSpzQaxsbNrTYW3jEk1AVw/ixuTu07
m30eGMSOG0CxHN2WkmUR7/4Pc660ox5OAY3SIokb+MX+gkw0jkElO0N8sPuv4Y22
IfdCZR16OPlfXjfSx/Lg9Rqhch3MwepzTGPMtSkMPmu98P9P4TZNclZdtUb4/hWv
gENDiMMb6DpCykCkzzVR0MHJI/+1gZfSBiOT2GONELFxoYBxxFhrJOb4ccBaw7UK
jPIk/wwtQkeKpkx0fJxoyvSjezJ5dras2SpXe8gyU743yV4yQI0CXUBI+2nUGpcF
lP4IWwMs7P6NF6WTKzexuv0J1vqobLSIZood1tIVm6qqmxhhu4N23l5s5x7Gtq3c
tb5PPs967KI7j+Z6VKtMw98UiII28/PF4eWutZmjmL/rlAC9hMw=
=24R+
-----END PGP SIGNATURE-----


Reply to: