[ubuntu/questing-security] node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1 (Accepted)

Shafayat Hossain Majumder shafayat.majumder at canonical.com
Tue Jun 9 14:45:59 UTC 2026


node-lodash (4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1) questing-security; urgency=medium

  * SECURITY UPDATE: prototype pollution in baseUnset
    - debian/patches/CVE-2025-13465.patch: add path traversal guards
      in baseUnset to block __proto__ and constructor.prototype paths in
      lodash.js, test/test.js.
    - CVE-2025-13465
  * SECURITY UPDATE: prototype pollution in baseUnset (bypass)
    - debian/patches/CVE-2026-2950.patch: use toKey() to normalize path
      segments and block constructor/prototype as non-terminal keys in
      lodash.js, test/test.js.
    - CVE-2026-2950
  * SECURITY UPDATE: command injection via _.template imports keys
    - debian/patches/CVE-2026-4800_1.patch: validate imports key names
      against reForbiddenIdentifierChars and switch assignInWith to
      assignWith in lodash.js, test/test.js.
    - debian/patches/CVE-2026-4800_2.patch: fix test references in
      test/test.js.
    - CVE-2026-4800

Date: 2026-06-08 21:24:08.387823+00:00
Changed-By: Shafayat Hossain Majumder <shafayat.majumder at canonical.com>
https://launchpad.net/ubuntu/+source/node-lodash/4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list