{"id":"DEBIAN-CVE-2026-2950","details":"Impact:  Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.  The issue permits deletion of prototype properties but does not allow overwriting their original behavior.  Patches:  This issue is patched in 4.18.0.  Workarounds:  None. Upgrade to the patched version.","modified":"2026-09-14T17:03:03.185808883Z","published":"2026-03-31T20:16:26.207Z","upstream":["CVE-2026-2950"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-2950"}],"affected":[{"package":{"name":"node-lodash","ecosystem":"Debian:12","purl":"pkg:deb/debian/node-lodash?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.17.21+dfsg+~cs8.31.198.20210220-10","4.17.21+dfsg+~cs8.31.198.20210220-9","4.17.23+dfsg-1","4.18.1+dfsg-1","4.18.1+dfsg-2","4.18.1+dfsg-3","4.18.1+dfsg1-1","4.18.1+dfsg1-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2950.json"}},{"package":{"name":"node-lodash","ecosystem":"Debian:13","purl":"pkg:deb/debian/node-lodash?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1"}]}],"versions":["4.17.21+dfsg+~cs8.31.198.20210220-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2950.json"}},{"package":{"name":"node-lodash","ecosystem":"Debian:14","purl":"pkg:deb/debian/node-lodash?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.18.1+dfsg-1"}]}],"versions":["4.17.21+dfsg+~cs8.31.198.20210220-10","4.17.21+dfsg+~cs8.31.198.20210220-9","4.17.23+dfsg-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-2950.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}