Skip to content

lodash upgrade to 4.17.23#8214

Merged
markdevocht merged 3 commits into
masterfrom
bugfix/lodash-vurnability-upgrade
Jan 28, 2026
Merged

lodash upgrade to 4.17.23#8214
markdevocht merged 3 commits into
masterfrom
bugfix/lodash-vurnability-upgrade

Conversation

@markdevocht
Copy link
Copy Markdown
Contributor

Upgrading lodash to 4.17.23, vulnerability fix:

CVE-2025-13465 (GHSA-xxjr-mmjv-4gpg)
Published: January 21, 2026 (5 days ago)
Severity: Moderate
Issue: Prototype Pollution in _.unset and _.omit functions
Affected: lodash 4.0.0 through 4.17.22
Fixed in: 4.17.23

@markdevocht markdevocht requested a review from gosha212 January 26, 2026 07:44
@markdevocht markdevocht linked an issue Jan 26, 2026 that may be closed by this pull request
1 task
@markdevocht markdevocht merged commit dbc4268 into master Jan 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

lodash vulnerability - need upgrade to 4.17.23

1 participant