CVE-2025-13465

Published Jan 21, 2026

Last updated 4 days ago

Overview

Description
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23
Source
ce714d77-add3-4f53-aff5-83d477b104bb
NVD status
Modified
Products
lodash

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

ce714d77-add3-4f53-aff5-83d477b104bb
CWE-1321
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-1321

Social media

Hype score
Not currently trending
  1. Next.js 16.3.0が公開。同梱lodashをCVE-2025-13465の修正版(4.17.23)へ更新し、依存経由の脆弱性リスクを解消。App Router周りのバグ修正やTurbopackのHMR改善も多数入っています。

    @tsumikasanedev

    14 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Next.js 16.3.0が同梱lodashの脆弱性CVE-2025-13465を修正。RSC周りのデプロイ不具合修正も入り、16系ユーザーは早めのパッチ適用が安心です。

    @tsumikasanedev

    12 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Next.js 16.3.0公開。同梱lodashのCVE-2025-13465を修正するセキュリティ対応入りで、16系利用者は早めの更新を推奨。TurbopackのHMR改善も地味に効きます。

    @tsumikasanedev

    10 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Next.js 16.3.0が公開。同梱lodashの脆弱性CVE-2025-13465を修正し、Turbopackのapp routeでHMRが有効に。Prisma Next 0.17は@prismaパッケージ構成に破壊的変更ありで、生成コードの書き換えが必要です。

    @tsumikasanedev

    9 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 今週の目玉はNext.js 16.3.0。同梱lodash由来のCVE-2025-13465を修正しており、16系を運用中なら上げ時です。Prisma Nextは0.17でパッケージ体系を破壊的に刷新、Docker 29.7系は回帰修正が続きました。合計24件のリリース週

    @tsumikasanedev

    8 Aug 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Next.js 16.3.0は同梱lodashのCVE-2025-13465修正入りで16系は上げ時。Prisma Nextは0.17でパッケージ構成が破壊的変更、@prisma単一化で移行に注意。Node.js 26.7も新機能多数。

    @tsumikasanedev

    6 Aug 2026

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Next.js 16.3.0がlodash由来のCVE-2025-13465を修正。RSCルートの不正なHTML応答やPages Routerのdata JSON応答も改善されました。16系を運用しているなら早めの取り込みを検討したいリリースです。

    @tsumikasanedev

    5 Aug 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. Next.js 16.3 patches CVE-2025-13465 and renames the HMR endpoint — check your proxy configs. LiteLLM gets Rust-backed Anthropic routing.

    @startupcorners_

    4 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🟠 HIGH (CVSS 8.2) — CVE-2025-13465 Published: 2026-01-21 lodash: prototype pollution in _[dot]unset and _[dot]omit functions 🧬 CVSS 3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H #CVE #CyberSecurity #InfoSec #Vulnerability ━━━━━━━━━━━

    @CVE2026COIN

    22 Jun 2026

    12 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨*CVE* CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://t.co/I2P3GU38NL… https://t.co/ASDj5M1WxX ----- Traducción: Impacto de CV… https://t.co/utmtNg

    @infoflowcloud

    1 Apr 2026

    184 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://t.co/Sr53IytKMp… https://t.co/wilANcmmSh

    @CVEnew

    1 Apr 2026

    253 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Just submitted my FIRST ever bug bounty report on @intigriti! Found a Prototype Pollution vulnerability via Lodash (CVE-2025-13465) — rated Medium severity, currently in Triage #BugBounty #Intigriti #CyberSecurity #Infosec #EthicalHacking #PenTest https://t.co/5cuuaJJj6m

    @muzakirbloch1

    8 Mar 2026

    140 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Critical patch for #openSUSE Leap 16.0: SLE-WU-2026-38129-5. It fixes prototype pollution in Cockpit (CVE-2025-13465) and js-yaml (CVE-2025-64718). Read more: 👉 https://t.co/X1YInsoZA8 #Security https://t.co/5x5ZaJIoQU

    @Cezar_H_Linux

    21 Feb 2026

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Deep-dive: #SUSE security update for Cockpit (CVE-2025-13465) is out. 🔒 Read more: 👉https://t.co/RDPKihUSmE #Security https://t.co/6PA2rtusxf

    @Cezar_H_Linux

    16 Feb 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Critical Patch Alert for #SUSE Linux Enterprise Server 16.0 The SUSE security team has released an urgent update for cockpit-packages to fix CVE-2025-13465, a prototype pollution flaw in the _.unset and _.omit functions. Read more: 👉 https://t.co/jFL2HTfPg9 #Security https:/

    @Cezar_H_Linux

    16 Feb 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. URGENT: #Fedora 42 security patch released for yarnpkg prototype pollution vulnerability (CVE-2025-13465). Read more: 👉 https://t.co/rN806nM2Tn #Security https://t.co/yL6Odt49wu

    @Cezar_H_Linux

    6 Feb 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Just published a deep dive on the critical pgAdmin 4 security update for #Fedora 42 (CVE-2025-13465). It's more than just a "run dnf update" notice. Read more: 👉 https://t.co/z80fo5PUWj #Security https://t.co/VBknMP9L2H

    @Cezar_H_Linux

    6 Feb 2026

    50 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🛠️ In-depth breakdown of the #security fix for CVE-2025-13465 in #Lodash: root cause, prototype pollution mechanics in _.unset/_.omit, and details of the patch. https://t.co/jnVlvggC4j

    @kom_256

    22 Jan 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. CVE-2025-13465: Lodash: The Delete Button for the Universe (CVE-2025-13465) A prototype pollution vulnerability in the ubiquitous Lodash library allows attackers to delete critical properties from the global Object prototype. Unlike traditional pollut... https://t.co/0jOaz03V3q

    @_cvereports

    22 Jan 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2025-13465 Prototype Pollution Vulnerability in Lodash _.unset and _.omit Functions https://t.co/2nTLBqtXX1

    @VulmonFeeds

    21 Jan 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CVE-2025-13465 Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash… https://t.co/pvBJst8bNj

    @CVEnew

    21 Jan 2026

    221 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.