Vulnerabilities/

Command Injection in lodash

Severity:
High

Description

lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Recommendation

Update the lodash package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
lodash
Anything's wrong? Let us know Last updated on August 12, 2025

This issue is available in SmartScanner Professional

See Pricing