Impact:

The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.

When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.

Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().

Patches:

Users should upgrade to version 4.18.0.

Workarounds:

Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4663-1 node-lodash security update
Github GHSA Github GHSA GHSA-r5fr-rjxr-66jc lodash vulnerable to Code Injection via `_.template` imports key names
Ubuntu USN Ubuntu USN USN-8411-1 Lodash vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:10131 cve-icon
https://access.redhat.com/errata/RHSA-2026:10175 cve-icon
https://access.redhat.com/errata/RHSA-2026:10710 cve-icon
https://access.redhat.com/errata/RHSA-2026:10713 cve-icon
https://access.redhat.com/errata/RHSA-2026:11454 cve-icon
https://access.redhat.com/errata/RHSA-2026:11469 cve-icon
https://access.redhat.com/errata/RHSA-2026:11470 cve-icon
https://access.redhat.com/errata/RHSA-2026:11471 cve-icon
https://access.redhat.com/errata/RHSA-2026:11493 cve-icon
https://access.redhat.com/errata/RHSA-2026:11494 cve-icon
https://access.redhat.com/errata/RHSA-2026:11495 cve-icon
https://access.redhat.com/errata/RHSA-2026:11516 cve-icon
https://access.redhat.com/errata/RHSA-2026:12277 cve-icon
https://access.redhat.com/errata/RHSA-2026:12279 cve-icon
https://access.redhat.com/errata/RHSA-2026:13545 cve-icon
https://access.redhat.com/errata/RHSA-2026:13553 cve-icon
https://access.redhat.com/errata/RHSA-2026:13571 cve-icon
https://access.redhat.com/errata/RHSA-2026:13826 cve-icon
https://access.redhat.com/errata/RHSA-2026:14870 cve-icon
https://access.redhat.com/errata/RHSA-2026:14871 cve-icon
https://access.redhat.com/errata/RHSA-2026:16874 cve-icon
https://access.redhat.com/errata/RHSA-2026:17448 cve-icon
https://access.redhat.com/errata/RHSA-2026:17468 cve-icon
https://access.redhat.com/errata/RHSA-2026:17469 cve-icon
https://access.redhat.com/errata/RHSA-2026:17547 cve-icon
https://access.redhat.com/errata/RHSA-2026:17549 cve-icon
https://access.redhat.com/errata/RHSA-2026:17550 cve-icon
https://access.redhat.com/errata/RHSA-2026:17598 cve-icon
https://access.redhat.com/errata/RHSA-2026:17789 cve-icon
https://access.redhat.com/errata/RHSA-2026:19008 cve-icon
https://access.redhat.com/errata/RHSA-2026:19167 cve-icon
https://access.redhat.com/errata/RHSA-2026:19409 cve-icon
https://access.redhat.com/errata/RHSA-2026:19410 cve-icon
https://access.redhat.com/errata/RHSA-2026:19712 cve-icon
https://access.redhat.com/errata/RHSA-2026:20041 cve-icon
https://access.redhat.com/errata/RHSA-2026:20042 cve-icon
https://access.redhat.com/errata/RHSA-2026:20943 cve-icon
https://access.redhat.com/errata/RHSA-2026:20946 cve-icon
https://access.redhat.com/errata/RHSA-2026:21658 cve-icon
https://access.redhat.com/errata/RHSA-2026:22619 cve-icon
https://access.redhat.com/errata/RHSA-2026:24331 cve-icon
https://access.redhat.com/errata/RHSA-2026:24762 cve-icon
https://access.redhat.com/errata/RHSA-2026:24977 cve-icon
https://access.redhat.com/errata/RHSA-2026:29795 cve-icon
https://access.redhat.com/errata/RHSA-2026:34100 cve-icon
https://access.redhat.com/errata/RHSA-2026:34342 cve-icon
https://access.redhat.com/errata/RHSA-2026:34608 cve-icon
https://access.redhat.com/errata/RHSA-2026:36621 cve-icon
https://access.redhat.com/errata/RHSA-2026:36651 cve-icon
https://access.redhat.com/errata/RHSA-2026:37186 cve-icon
https://access.redhat.com/errata/RHSA-2026:40118 cve-icon
https://access.redhat.com/errata/RHSA-2026:40795 cve-icon
https://access.redhat.com/errata/RHSA-2026:40945 cve-icon
https://access.redhat.com/errata/RHSA-2026:40984 cve-icon
https://access.redhat.com/errata/RHSA-2026:41928 cve-icon
https://access.redhat.com/errata/RHSA-2026:41941 cve-icon
https://access.redhat.com/errata/RHSA-2026:41944 cve-icon
https://access.redhat.com/errata/RHSA-2026:42078 cve-icon
https://access.redhat.com/errata/RHSA-2026:44235 cve-icon
https://access.redhat.com/errata/RHSA-2026:48699 cve-icon
https://access.redhat.com/errata/RHSA-2026:8483 cve-icon
https://access.redhat.com/errata/RHSA-2026:8484 cve-icon
https://access.redhat.com/errata/RHSA-2026:8490 cve-icon
https://access.redhat.com/errata/RHSA-2026:8491 cve-icon
https://access.redhat.com/errata/RHSA-2026:8493 cve-icon
https://access.redhat.com/errata/RHSA-2026:8498 cve-icon
https://access.redhat.com/errata/RHSA-2026:9385 cve-icon
https://access.redhat.com/errata/RHSA-2026:9742 cve-icon
https://access.redhat.com/security/cve/CVE-2026-4800 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2453496 cve-icon
https://cna.openjsf.org/security-advisories.html cve-icon cve-icon cve-icon
https://github.com/advisories/GHSA-35jh-r3h4-6jhm cve-icon cve-icon cve-icon
https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-4800 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4800.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-4800 cve-icon
History

Fri, 01 May 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Lodash lodash-amd
CPEs cpe:2.3:a:lodash:lodash-rails:*:*:*:*:*:ruby:*:* cpe:2.3:a:lodash:lodash-amd:*:*:*:*:*:node.js:*:*
Vendors & Products Lodash lodash-rails
Lodash lodash-amd

Tue, 07 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Lodash lodash-es
Lodash lodash-rails
CPEs cpe:2.3:a:lodash:lodash-es:*:*:*:*:*:node.js:*:*
cpe:2.3:a:lodash:lodash-rails:*:*:*:*:*:ruby:*:*
cpe:2.3:a:lodash:lodash.template:*:*:*:*:*:node.js:*:*
cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*
Vendors & Products Lodash lodash-es
Lodash lodash-rails

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Lodash
Lodash lodash
Lodash lodash.template
Vendors & Products Lodash
Lodash lodash
Lodash lodash.template

Thu, 02 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
Description Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.
Title lodash vulnerable to Code Injection via `_.template` imports key names
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-08-12T12:04:39.698Z

Reserved: 2026-03-25T09:12:38.355Z

Link: CVE-2026-4800

cve-icon Vulnrichment

Updated: 2026-08-12T12:04:39.698Z

cve-icon NVD

Status : Modified

Published: 2026-03-31T20:16:29.660

Modified: 2026-08-12T12:19:38.517

Link: CVE-2026-4800

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-31T19:25:55Z

Links: CVE-2026-4800 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T20:00:14Z

Weaknesses