[ubuntu/questing-security] node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1 (Accepted)
Shafayat Hossain Majumder
shafayat.majumder at canonical.com
Tue Jun 9 14:45:59 UTC 2026
node-lodash (4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1) questing-security; urgency=medium
* SECURITY UPDATE: prototype pollution in baseUnset
- debian/patches/CVE-2025-13465.patch: add path traversal guards
in baseUnset to block __proto__ and constructor.prototype paths in
lodash.js, test/test.js.
- CVE-2025-13465
* SECURITY UPDATE: prototype pollution in baseUnset (bypass)
- debian/patches/CVE-2026-2950.patch: use toKey() to normalize path
segments and block constructor/prototype as non-terminal keys in
lodash.js, test/test.js.
- CVE-2026-2950
* SECURITY UPDATE: command injection via _.template imports keys
- debian/patches/CVE-2026-4800_1.patch: validate imports key names
against reForbiddenIdentifierChars and switch assignInWith to
assignWith in lodash.js, test/test.js.
- debian/patches/CVE-2026-4800_2.patch: fix test references in
test/test.js.
- CVE-2026-4800
Date: 2026-06-08 21:24:08.387823+00:00
Changed-By: Shafayat Hossain Majumder <shafayat.majumder at canonical.com>
https://launchpad.net/ubuntu/+source/node-lodash/4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list