Description
lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
- GHSA-35jh-r3h4-6jhm
- snyk.io
- www.oracle.com
- cert-portal.siemens.com
- security.netapp.com
- CVE-2021-23337
- CWE-77
- CWE-94
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Command Injection in lodash - lodash-es - CVE-2021-23337
- Command Injection in lodash - CVE-2021-23337
- GraphiQL introspection schema template injection attack - CVE-2021-41248
- lodash vulnerable to Code Injection via `_.template` imports key names - CVE-2026-4800
You might also like:
- Tags:
- npm
- lodash-template
Anything's wrong? Let us know Last updated on August 12, 2025


