Command Injection in lodash
High severity
GitHub Reviewed
Published
May 6, 2021
to the GitHub Advisory Database
•
Updated Aug 12, 2025
Description
Published by the National Vulnerability Database
Feb 15, 2021
Reviewed
Mar 31, 2021
Published to the GitHub Advisory Database
May 6, 2021
Last updated
Aug 12, 2025
lodash
versions prior to 4.17.21 are vulnerable to Command Injection via the template function.References