Vulnerabilities/

Command Injection in lodash - lodash-template

Severity:
High

Description

lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
lodash-template
Anything's wrong? Let us know Last updated on August 12, 2025