[SECURITY] [DLA 4663-1] node-lodash security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -----------------------------------------------------------------------
Debian LTS Advisory DLA-4663-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Utkarsh Gupta
July 02, 2026 https://wiki.debian.org/LTS
- -----------------------------------------------------------------------
Package : node-lodash
Version : 4.17.21+dfsg+~cs8.31.173-1+deb11u1
CVE ID : CVE-2025-13465 CVE-2026-2950 CVE-2026-4800
Debian Bug : 1126265
Several vulnerabilities were discovered in node-lodash, a Node.js
module providing utility functions for common programming tasks.
CVE-2025-13465
Prototype pollution in the _.unset and _.omit functions. A
crafted property path could be used to delete properties from
built-in prototypes (such as Object.prototype), leading to
availability and integrity issues.
CVE-2026-2950
An incomplete fix for CVE-2025-13465. The initial guard only
handled string key members and the literal "constructor.prototype"
sequence, so it could be bypassed using array-wrapped path
segments (for example [['constructor'], ['keys']]), via
constructor static methods, or from primitive roots, again allowing
deletion of properties on shared built-in prototypes.
CVE-2026-4800
Code injection in the _.template function. An incomplete fix for
CVE-2021-23337: the "variable" option was validated but the
"imports" option key names were not. Untrusted input passed as
imports key names could inject default-parameter expressions that
execute arbitrary code at template compilation time via the same
Function() constructor sink.
For Debian 11 bullseye, this problem has been fixed in version
4.17.21+dfsg+~cs8.31.173-1+deb11u1.
We recommend that you upgrade your node-lodash packages.
For the detailed security status of node-lodash please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/node-lodash
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpFkjUACgkQgj6WdgbD
S5Y75RAA6UU8qCYcHXO3yINyAEkLrQ1ZfCwESeGJX/4ChH5TRwp+jh///6UUapY3
ct3tJRZHq0qpDhjHn/G00x5P9uToN9J6/MCwPKq9dnHEb22xAHatSUmEmpl589i3
KIG2VxT9j4USBfoLjRrU8AozOniTYL49GXsO4n9AlTVDMhZ/UUKI/AZTP9X2UGt3
e/CUaN1tlfE200UXbcKfqAI5+IL3LC4cN56AHCeYBrmeB1T62CEz7oGPbqNWyayb
BzqYqNKxBODExSbHXWEhegA4eB/vSJGTAEYSpzQaxsbNrTYW3jEk1AVw/ixuTu07
m30eGMSOG0CxHN2WkmUR7/4Pc660ox5OAY3SIokb+MX+gkw0jkElO0N8sPuv4Y22
IfdCZR16OPlfXjfSx/Lg9Rqhch3MwepzTGPMtSkMPmu98P9P4TZNclZdtUb4/hWv
gENDiMMb6DpCykCkzzVR0MHJI/+1gZfSBiOT2GONELFxoYBxxFhrJOb4ccBaw7UK
jPIk/wwtQkeKpkx0fJxoyvSjezJ5dras2SpXe8gyU743yV4yQI0CXUBI+2nUGpcF
lP4IWwMs7P6NF6WTKzexuv0J1vqobLSIZood1tIVm6qqmxhhu4N23l5s5x7Gtq3c
tb5PPs967KI7j+Z6VKtMw98UiII28/PF4eWutZmjmL/rlAC9hMw=
=24R+
-----END PGP SIGNATURE-----
Reply to: