Description
Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for CVE-2025-13465 only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.
Recommendation
Update the lodash-es package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.17.23
- Patched version(s): 4.18.0
References
Could your website be exposed too?
SmartScanner can check your website for lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-es and gives you actionable findings to investigate.
Start a free scanRelated Issues
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash.unset - CVE-2026-2950
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - CVE-2026-2950
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-amd - CVE-2026-2950
- dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform() - CVE-2026-27837


