CVE-2025-13465

Published Jan 21, 2026

Last updated 2 months ago

Overview

Description
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23
Source
ce714d77-add3-4f53-aff5-83d477b104bb
NVD status
Analyzed
Products
lodash

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

ce714d77-add3-4f53-aff5-83d477b104bb
CWE-1321

Social media

Hype score
Not currently trending
  1. 🚨*CVE* CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://t.co/I2P3GU38NL… https://t.co/ASDj5M1WxX ----- Traducción: Impacto de CV… https://t.co/utmtNg

    @infoflowcloud

    1 Apr 2026

    184 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://t.co/Sr53IytKMp… https://t.co/wilANcmmSh

    @CVEnew

    1 Apr 2026

    253 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Just submitted my FIRST ever bug bounty report on @intigriti! Found a Prototype Pollution vulnerability via Lodash (CVE-2025-13465) — rated Medium severity, currently in Triage #BugBounty #Intigriti #CyberSecurity #Infosec #EthicalHacking #PenTest https://t.co/5cuuaJJj6m

    @muzakirbloch1

    8 Mar 2026

    140 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Critical patch for #openSUSE Leap 16.0: SLE-WU-2026-38129-5. It fixes prototype pollution in Cockpit (CVE-2025-13465) and js-yaml (CVE-2025-64718). Read more: 👉 https://t.co/X1YInsoZA8 #Security https://t.co/5x5ZaJIoQU

    @Cezar_H_Linux

    21 Feb 2026

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Deep-dive: #SUSE security update for Cockpit (CVE-2025-13465) is out. 🔒 Read more: 👉https://t.co/RDPKihUSmE #Security https://t.co/6PA2rtusxf

    @Cezar_H_Linux

    16 Feb 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Critical Patch Alert for #SUSE Linux Enterprise Server 16.0 The SUSE security team has released an urgent update for cockpit-packages to fix CVE-2025-13465, a prototype pollution flaw in the _.unset and _.omit functions. Read more: 👉 https://t.co/jFL2HTfPg9 #Security https:/

    @Cezar_H_Linux

    16 Feb 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. URGENT: #Fedora 42 security patch released for yarnpkg prototype pollution vulnerability (CVE-2025-13465). Read more: 👉 https://t.co/rN806nM2Tn #Security https://t.co/yL6Odt49wu

    @Cezar_H_Linux

    6 Feb 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Just published a deep dive on the critical pgAdmin 4 security update for #Fedora 42 (CVE-2025-13465). It's more than just a "run dnf update" notice. Read more: 👉 https://t.co/z80fo5PUWj #Security https://t.co/VBknMP9L2H

    @Cezar_H_Linux

    6 Feb 2026

    50 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛠️ In-depth breakdown of the #security fix for CVE-2025-13465 in #Lodash: root cause, prototype pollution mechanics in _.unset/_.omit, and details of the patch. https://t.co/jnVlvggC4j

    @kom_256

    22 Jan 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2025-13465: Lodash: The Delete Button for the Universe (CVE-2025-13465) A prototype pollution vulnerability in the ubiquitous Lodash library allows attackers to delete critical properties from the global Object prototype. Unlike traditional pollut... https://t.co/0jOaz03V3q

    @_cvereports

    22 Jan 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2025-13465 Prototype Pollution Vulnerability in Lodash _.unset and _.omit Functions https://t.co/2nTLBqtXX1

    @VulmonFeeds

    21 Jan 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2025-13465 Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash… https://t.co/pvBJst8bNj

    @CVEnew

    21 Jan 2026

    221 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.