Lodash Patches High-Severity Code Injection Vulnerability
ID: 798dc098-6e7a-5dfc-acea-42ca92ad01de
STIX ID: report--798dc098-6e7a-5dfc-acea-42ca92ad01de
Feed Name: securityonline.info
An advisory for CVE-2026-4800: a high-severity (CVSS 8.1) code-injection vulnerability in Lodash's _.template function caused by lack of validation for options.imports key names. Untrusted keys can inject default-parameter expressions that execute via the Function() constructor, and the issue is worsened by assignInWith merging which copies inherited (potentially polluted) properties — upgrade to Lodash 4.18.0 immediately or ensure only developer-controlled import key names are used.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
