Vulnerabilities/

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-es

Severity:
Medium

Description

Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for CVE-2025-13465 only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.

Recommendation

Update the lodash-es package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
lodash-es
Anything's wrong? Let us know Last updated on April 01, 2026