Feed/CVE-2026-2950
CVE-2026-2950

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

Published Jun 30, 2026·Updated Jun 30, 2026

NVD Description

### Impact Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the `_.unset` and `_.omit` functions. The fix for [CVE-2025-13465](https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as `Object.prototype`, `Number.prototype`, and `String.prototype`. The issue permits deletion of prototype properties but does not allow overwriting their original behavior. ### Patches This issue is patched in 4.18.0. ### Workarounds None. Upgrade to the patched version.

Affected Packages (2)

lodashNPM
Fixed in 4.18.0
lodashNPM
From 4.0.0
Fixed in 4.18.0

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free