|
|
Log in / Subscribe / Register

Debian alert DLA-4663-1 (node-lodash)

From:  Utkarsh Gupta <utkarsh@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4663-1] node-lodash security update
Date:  Thu, 02 Jul 2026 03:48:49 +0530
Message-ID:  <CAPP0f94UVg4Q-EvtJ0hPX88xmcDHLufyktTwUARtgdxoAKGbCg@mail.gmail.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-4663-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta July 02, 2026 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : node-lodash Version : 4.17.21+dfsg+~cs8.31.173-1+deb11u1 CVE ID : CVE-2025-13465 CVE-2026-2950 CVE-2026-4800 Debian Bug : 1126265 Several vulnerabilities were discovered in node-lodash, a Node.js module providing utility functions for common programming tasks. CVE-2025-13465 Prototype pollution in the _.unset and _.omit functions. A crafted property path could be used to delete properties from built-in prototypes (such as Object.prototype), leading to availability and integrity issues. CVE-2026-2950 An incomplete fix for CVE-2025-13465. The initial guard only handled string key members and the literal "constructor.prototype" sequence, so it could be bypassed using array-wrapped path segments (for example [['constructor'], ['keys']]), via constructor static methods, or from primitive roots, again allowing deletion of properties on shared built-in prototypes. CVE-2026-4800 Code injection in the _.template function. An incomplete fix for CVE-2021-23337: the "variable" option was validated but the "imports" option key names were not. Untrusted input passed as imports key names could inject default-parameter expressions that execute arbitrary code at template compilation time via the same Function() constructor sink. For Debian 11 bullseye, this problem has been fixed in version 4.17.21+dfsg+~cs8.31.173-1+deb11u1. We recommend that you upgrade your node-lodash packages. For the detailed security status of node-lodash please refer to its security tracker page at: https://security-tracker.debian.org/tracker/node-lodash Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpFkjUACgkQgj6WdgbD S5Y75RAA6UU8qCYcHXO3yINyAEkLrQ1ZfCwESeGJX/4ChH5TRwp+jh///6UUapY3 ct3tJRZHq0qpDhjHn/G00x5P9uToN9J6/MCwPKq9dnHEb22xAHatSUmEmpl589i3 KIG2VxT9j4USBfoLjRrU8AozOniTYL49GXsO4n9AlTVDMhZ/UUKI/AZTP9X2UGt3 e/CUaN1tlfE200UXbcKfqAI5+IL3LC4cN56AHCeYBrmeB1T62CEz7oGPbqNWyayb BzqYqNKxBODExSbHXWEhegA4eB/vSJGTAEYSpzQaxsbNrTYW3jEk1AVw/ixuTu07 m30eGMSOG0CxHN2WkmUR7/4Pc660ox5OAY3SIokb+MX+gkw0jkElO0N8sPuv4Y22 IfdCZR16OPlfXjfSx/Lg9Rqhch3MwepzTGPMtSkMPmu98P9P4TZNclZdtUb4/hWv gENDiMMb6DpCykCkzzVR0MHJI/+1gZfSBiOT2GONELFxoYBxxFhrJOb4ccBaw7UK jPIk/wwtQkeKpkx0fJxoyvSjezJ5dras2SpXe8gyU743yV4yQI0CXUBI+2nUGpcF lP4IWwMs7P6NF6WTKzexuv0J1vqobLSIZood1tIVm6qqmxhhu4N23l5s5x7Gtq3c tb5PPs967KI7j+Z6VKtMw98UiII28/PF4eWutZmjmL/rlAC9hMw= =24R+ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds