Skip to content

fix(npm): patch lodash - #1

Open
Ar9av wants to merge 1 commit into
mainfrom
patchbot-npm-lodash
Open

fix(npm): patch lodash#1
Ar9av wants to merge 1 commit into
mainfrom
patchbot-npm-lodash

Conversation

@Ar9av

@Ar9av Ar9av commented Aug 24, 2026

Copy link
Copy Markdown
Collaborator

Fix the following security advisories affecting npm package 'lodash' (currently 4.17.20) in this repository.

  • GHSA-29mw-wpgm-hmr9 (low): Regular Expression Denial of Service (ReDoS) in lodash. Fixed in: 4.17.21.
  • GHSA-35jh-r3h4-6jhm (high): Command Injection in lodash. Fixed in: 4.17.21.
  • GHSA-f23m-r3pf-42rh (low): lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit. Fixed in: 4.18.0.
  • GHSA-r5fr-rjxr-66jc (high): lodash vulnerable to Code Injection via _.template imports key names. Fixed in: 4.18.0.
  • GHSA-xxjr-mmjv-4gpg (low): Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions. Fixed in: 4.17.23.

Bump the package to 4.18.0 in every manifest and lockfile that references it, then update the lockfile using the project's package manager so it stays in sync. Do not modify unrelated files or unrelated dependencies.

Fixed by: bump tier.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant