- Description
- Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23
- Source
- ce714d77-add3-4f53-aff5-83d477b104bb
- NVD status
- Modified
- Products
- lodash
CVSS 4.0
- Type
- Secondary
- Base score
- 6.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity
- MEDIUM
- Hype score
- Not currently trending
Next.js 16.3.0が公開。同梱lodashをCVE-2025-13465の修正版(4.17.23)へ更新し、依存経由の脆弱性リスクを解消。App Router周りのバグ修正やTurbopackのHMR改善も多数入っています。
@tsumikasanedev
14 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Next.js 16.3.0が同梱lodashの脆弱性CVE-2025-13465を修正。RSC周りのデプロイ不具合修正も入り、16系ユーザーは早めのパッチ適用が安心です。
@tsumikasanedev
12 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Next.js 16.3.0公開。同梱lodashのCVE-2025-13465を修正するセキュリティ対応入りで、16系利用者は早めの更新を推奨。TurbopackのHMR改善も地味に効きます。
@tsumikasanedev
10 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Next.js 16.3.0が公開。同梱lodashの脆弱性CVE-2025-13465を修正し、Turbopackのapp routeでHMRが有効に。Prisma Next 0.17は@prismaパッケージ構成に破壊的変更ありで、生成コードの書き換えが必要です。
@tsumikasanedev
9 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
今週の目玉はNext.js 16.3.0。同梱lodash由来のCVE-2025-13465を修正しており、16系を運用中なら上げ時です。Prisma Nextは0.17でパッケージ体系を破壊的に刷新、Docker 29.7系は回帰修正が続きました。合計24件のリリース週
@tsumikasanedev
8 Aug 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Next.js 16.3.0は同梱lodashのCVE-2025-13465修正入りで16系は上げ時。Prisma Nextは0.17でパッケージ構成が破壊的変更、@prisma単一化で移行に注意。Node.js 26.7も新機能多数。
@tsumikasanedev
6 Aug 2026
60 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Next.js 16.3.0がlodash由来のCVE-2025-13465を修正。RSCルートの不正なHTML応答やPages Routerのdata JSON応答も改善されました。16系を運用しているなら早めの取り込みを検討したいリリースです。
@tsumikasanedev
5 Aug 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Next.js 16.3 patches CVE-2025-13465 and renames the HMR endpoint — check your proxy configs. LiteLLM gets Rust-backed Anthropic routing.
@startupcorners_
4 Aug 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🟠 HIGH (CVSS 8.2) — CVE-2025-13465 Published: 2026-01-21 lodash: prototype pollution in _[dot]unset and _[dot]omit functions 🧬 CVSS 3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H #CVE #CyberSecurity #InfoSec #Vulnerability ━━━━━━━━━━━
@CVE2026COIN
22 Jun 2026
12 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://t.co/I2P3GU38NL… https://t.co/ASDj5M1WxX ----- Traducción: Impacto de CV… https://t.co/utmtNg
@infoflowcloud
1 Apr 2026
184 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://t.co/Sr53IytKMp… https://t.co/wilANcmmSh
@CVEnew
1 Apr 2026
253 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Just submitted my FIRST ever bug bounty report on @intigriti! Found a Prototype Pollution vulnerability via Lodash (CVE-2025-13465) — rated Medium severity, currently in Triage #BugBounty #Intigriti #CyberSecurity #Infosec #EthicalHacking #PenTest https://t.co/5cuuaJJj6m
@muzakirbloch1
8 Mar 2026
140 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Critical patch for #openSUSE Leap 16.0: SLE-WU-2026-38129-5. It fixes prototype pollution in Cockpit (CVE-2025-13465) and js-yaml (CVE-2025-64718). Read more: 👉 https://t.co/X1YInsoZA8 #Security https://t.co/5x5ZaJIoQU
@Cezar_H_Linux
21 Feb 2026
60 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Deep-dive: #SUSE security update for Cockpit (CVE-2025-13465) is out. 🔒 Read more: 👉https://t.co/RDPKihUSmE #Security https://t.co/6PA2rtusxf
@Cezar_H_Linux
16 Feb 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Patch Alert for #SUSE Linux Enterprise Server 16.0 The SUSE security team has released an urgent update for cockpit-packages to fix CVE-2025-13465, a prototype pollution flaw in the _.unset and _.omit functions. Read more: 👉 https://t.co/jFL2HTfPg9 #Security https:/
@Cezar_H_Linux
16 Feb 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
URGENT: #Fedora 42 security patch released for yarnpkg prototype pollution vulnerability (CVE-2025-13465). Read more: 👉 https://t.co/rN806nM2Tn #Security https://t.co/yL6Odt49wu
@Cezar_H_Linux
6 Feb 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Just published a deep dive on the critical pgAdmin 4 security update for #Fedora 42 (CVE-2025-13465). It's more than just a "run dnf update" notice. Read more: 👉 https://t.co/z80fo5PUWj #Security https://t.co/VBknMP9L2H
@Cezar_H_Linux
6 Feb 2026
50 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🛠️ In-depth breakdown of the #security fix for CVE-2025-13465 in #Lodash: root cause, prototype pollution mechanics in _.unset/_.omit, and details of the patch. https://t.co/jnVlvggC4j
@kom_256
22 Jan 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-13465: Lodash: The Delete Button for the Universe (CVE-2025-13465) A prototype pollution vulnerability in the ubiquitous Lodash library allows attackers to delete critical properties from the global Object prototype. Unlike traditional pollut... https://t.co/0jOaz03V3q
@_cvereports
22 Jan 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-13465 Prototype Pollution Vulnerability in Lodash _.unset and _.omit Functions https://t.co/2nTLBqtXX1
@VulmonFeeds
21 Jan 2026
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-13465 Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash… https://t.co/pvBJst8bNj
@CVEnew
21 Jan 2026
221 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "0F9E287B-784B-472D-9FA2-1469E4C8A810",
"versionEndExcluding": "4.17.23",
"versionStartIncluding": "4.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]