GHSA-r5fr-rjxr-66jc

    Dashboard / Vulnerabilities / GHSA-r5fr-rjxr-66jc

    GHSA-r5fr-rjxr-66jc

    Published: 1 Apr 2026Last Modified: 10 Sept 2026

    Summary: lodash vulnerable to Code Injection via `_.template` imports key names

    Details: ### Impact The fix for [CVE-2021-23337](https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the `variable` option in `_.template` but did not apply the same validation to `options.imports` key names. Both paths flow into the same `Function()` constructor sink. When an application passes untrusted input as `options.imports` key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, `_.template` uses `assignInWith` to merge imports, which enumerates inherited properties via `for..in`. If `Object.prototype` has been polluted by any other vector, the polluted keys are copied into the imports object and passed to `Function()`. ### Patches Users should upgrade to version 4.18.0. The fix applies two changes: 1. Validate `importsKeys` against the existing `reForbiddenIdentifierChars` regex (same check already used for the `variable` option) 2. Replace `assignInWith` with `assignWith` when merging imports, so only own properties are enumerated ### Workarounds Do not pass untrusted input as key names in `options.imports`. Only use developer-controlled, static key names.

    Affected packages

    Package

    Name: lodash

    Purl: pkg:npm/lodash

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.0.0
    Fixed -4.18.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-r5fr-rjxr-66jc | CVE-DB