Vulnerabilities/

Arbitrary Code Execution in underscore

Severity:
High

Description

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Recommendation

Update the underscore package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
underscore
Anything's wrong? Let us know Last updated on November 04, 2025