« Volver al listado

CVE-2026-2950

Estado: AnalizadaMedia (5.3)—

Impact:

Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.

The issue permits deletion of prototype properties but does not allow overwriting their original behavior.

Patches:

This issue is patched in 4.18.0.

Leer descripción completaMostrar menos

Workarounds:

None. Upgrade to the patched version.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-2950",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-2950",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-01T13:43:14.280375Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "affectedData": [
        {
          "vendor": "lodash",
          "product": "lodash",
          "versions": [
            {
              "status": "affected",
              "version": "4.17.23",
              "lessThan": "4.18.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.18.0",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/lodash",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "lodash",
          "product": "lodash-es",
          "versions": [
            {
              "status": "affected",
              "version": "4.17.23",
              "lessThan": "4.18.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.18.0",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/lodash-es",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "lodash",
          "product": "lodash-amd",
          "versions": [
            {
              "status": "affected",
              "version": "4.17.23",
              "lessThan": "4.18.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.18.0",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/lodash-amd",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "lodash",
          "product": "lodash.unset",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.18.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.18.0",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/lodash.unset",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-31T20:16:26.207",
  "references": [
    {
      "url": "https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1321"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Impact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prototype properties but does not allow overwriting their original behavior.\n\nPatches:\n\nThis issue is patched in 4.18.0.\n\nWorkarounds:\n\nNone. Upgrade to the patched version."
    },
    {
      "lang": "es",
      "value": "Impacto:\n\nLas versiones de Lodash 4.17.23 y anteriores son vulnerables a la contaminación de prototipos en las funciones _.unset y _.omit. La solución para (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) solo protege contra miembros de clave de tipo cadena, por lo que un atacante puede eludir la verificación pasando segmentos de ruta envueltos en arrays. Esto permite la eliminación de propiedades de prototipos incorporados como Object.prototype, Number.prototype y String.prototype.\n\nEl problema permite la eliminación de propiedades de prototipo, pero no permite sobrescribir su comportamiento original.\n\nParches:\n\nEste problema está parcheado en 4.18.0.\n\nSoluciones alternativas:\n\nNinguna. Actualice a la versión parcheada."
    }
  ],
  "lastModified": "2026-07-24T20:10:00.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F9E287B-784B-472D-9FA2-1469E4C8A810",
              "versionEndExcluding": "4.17.23",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:lodash:lodash-amd:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A1B5527-B25F-49B8-A289-E964EFFCF4E4",
              "versionEndExcluding": "4.17.23",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:lodash:lodash-es:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C20325C-6B92-4775-89D7-2650F158B622",
              "versionEndExcluding": "4.17.23",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:lodash:lodash.unset:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43DC850D-9F26-4445-BAB1-9AF9BA37095C",
              "versionStartIncluding": "4.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}