Prototype pollution in Lodash - CVE-2025-13465

 

Prototype pollution in Lodash - CVE-2025-13465

Published: January 22, 2026


Vulnerability identifier: #VU121928
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-13465
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to alter application's behavior. 

The vulnerability exists due to improper input validation within the in the _.unset and _.omit functions. A remote attacker can pass specially crafted input to the application and delete methods from global prototypes.


Affected software

Lodash
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro for Rancher
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Netezza Appliance
Storage Sentinel Anomaly Scan Engine
Storage Defender Copy Data Management
Guardium Data Security Center (GDSC)
Storage Fusion Data Foundation
watsonx Code Assistant On Prem
Storage Scale
MongoDB Enterprise Advanced with IBM
Maximo Application Suite - Visual Inspection Component
Maximo Application Suite - Monitor Component
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Db2 Big SQL
Maximo Scheduler Optimizer
InfoSphere Optim Archive Viewer
Robotic Process Automation for Cloud Pak
Voice Gateway
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM SPSS Collaboration and Deployment Services
IBM Business Automation Workflow
Ansible Automation Platform
App Connect Enterprise Certified Container
Event Streams
IBM QRadar Data Synchronization App
JBoss Data Grid
IBM DataPower Gateway
Red Hat OpenShift Container Platform
IBM App Connect Enterprise
IBM Security SOAR
mgrctl
mgrctl-debuginfo
mgrctl-lang
mgrctl-zsh-completion
mgrctl-bash-completion
firewalld-prometheus-config
golang-github-QubitProducts-exporter_exporter
pcs (Red Hat package)
pcs
golang-github-prometheus-promu-debuginfo
golang-github-prometheus-promu
prometheus-blackbox_exporter
golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter-debuginfo
dracut-saltboot
golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter-debuginfo
python-jupytext
yarnpkg
node-lodash (Ubuntu package)
linux-sgx
golang-github-prometheus-prometheus
release-notes-susemanager-proxy
release-notes-susemanager
openqa
spacecmd
pgadmin4
python3.12-pillow-debugsource (Red Hat package)
grafana
grafana-debuginfo
nextcloud
cockpit-podman
cockpit-image-builder (Red Hat package)
cockpit-machines
cockpit-debugsource
cockpit
cockpit-debuginfo
cockpit-ws
cockpit-system
cockpit-bridge
cockpit-bridge-debuginfo
cockpit-ws-debuginfo
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2025-13465

Install updates from vendor's website.

Lodash - update to 4.17.23
Netezza Appliance - update to 1.0.1.0 fp278500
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.18, 1.0.8.24, 1.0.8.29
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
Storage Defender Copy Data Management - update to 2.3.0.1
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.18-sc2, 4.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Code Assistant On Prem - update to 5.3.1
Storage Scale - addressed in versions 5.2.3.7, 6.0.0.2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
MongoDB Enterprise Advanced with IBM - update to 8.0.20
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.37, 8.7.31, 9.0.24, 9.1.14
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.21, 9.0.19, 9.1.12
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite - Monitor Component - addressed in versions 8.10.29, 8.11.27, 9.0.19, 9.1.9
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0.2
Event Streams - update to 13.0.0
IBM DataPower Gateway - addressed in versions 10.5.0.21, 10.6.0.9, 11.0.0.0
DevOps Test Performance - update to 11.0.8
IBM App Connect Enterprise - addressed in versions 12.0.12.24, 13.0.6.2
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - update to 16.1.3.4
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Security SOAR - update to 51.0.9.0
mgrctl - update to 0.1.38-150000.1.30.1
mgrctl-debuginfo - update to 0.1.38-150000.1.30.1
mgrctl-lang - update to 0.1.38-150000.1.30.1
mgrctl-zsh-completion - update to 0.1.38-150000.1.30.1
mgrctl-bash-completion - update to 0.1.38-150000.1.30.1
firewalld-prometheus-config - update to 0.1-150000.3.67.1
golang-github-QubitProducts-exporter_exporter - update to 0.4.0-150000.1.21.1
pcs (Red Hat package) - addressed in versions 0.10.8-1.el8_4.10, 0.10.12-6.el8_6.12, 0.10.15-4.el8_8.10, 0.11.1-10.el9_0.10, 0.11.4-7.el9_2.7, 0.11.7-2.el9_4.6, 0.11.9-2.el9_6.3, 0.11.10-1.el9_7.2, 0.12.0-3.el10_0.4, 0.12.1-1.el10_1.2
pcs - addressed in versions 0.12.2-1.fc42, 0.12.2-1.fc43, 0.12.2-1.fc45
golang-github-prometheus-promu-debuginfo - update to 0.17.0-150000.3.30.1
golang-github-prometheus-promu - update to 0.17.0-150000.3.30.1
prometheus-blackbox_exporter - update to 0.26.0-150000.1.30.2
golang-github-lusitaniae-apache_exporter - update to 1.0.10-150000.1.26.1
golang-github-lusitaniae-apache_exporter-debuginfo - update to 1.0.10-150000.1.26.1
dracut-saltboot - update to 1.1.0-150000.1.65.1
golang-github-boynux-squid_exporter - update to 1.13.0-150000.1.12.1
golang-github-boynux-squid_exporter-debuginfo - update to 1.13.0-150000.1.12.1
python-jupytext - addressed in versions 1.19.1-1.fc42, 1.19.1-1.fc43
yarnpkg - addressed in versions 1.22.22-16.el9, 1.22.22-16.el10_2, 1.22.22-16.fc42, 1.22.22-16.fc43
node-lodash (Ubuntu package) - addressed in versions 2.4.1+dfsg-3ubuntu0.1~esm1, 4.17.4+dfsg-1ubuntu0.1~esm1, 4.17.15+dfsg-2ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1, 4.17.23+dfsg-1ubuntu0.1~esm1
Ansible Automation Platform - update to 2.6
linux-sgx - update to 2.26-34.fc43
golang-github-prometheus-prometheus - update to 3.5.0-150000.3.67.1
IBM QRadar Data Synchronization App - update to 4.0.0
release-notes-susemanager-proxy - update to 4.3.17-150400.3.107.1
release-notes-susemanager - update to 4.3.17-150400.3.151.1
Red Hat OpenShift Container Platform - update to 4.17.55
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
openqa - update to 5^20250711git28a0214-4.fc42
spacecmd - update to 5.0.15-150000.3.142.1
Db2 Big SQL - update to 8.3.1 patch 4
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
JBoss Data Grid - update to 8.6.0
pgadmin4 - addressed in versions 9.11-3.fc42, 9.11-3.fc43
python3.12-pillow-debugsource (Red Hat package) - update to 10.3.0-2.el9ap
grafana - update to 11.6.11-150000.1.90.1
grafana-debuginfo - update to 11.6.11-150000.1.90.1
InfoSphere Optim Archive Viewer - update to 11.7.0.14
App Connect Enterprise Certified Container - addressed in versions 12.0.21, 12.21.0
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
nextcloud - addressed in versions 32.0.6-1.el10_1, 32.0.6-1.el10_2, 32.0.6-1.fc42, 32.0.6-1.fc43, 32.0.6-1.fc44
cockpit-podman - update to 33-150300.6.6.1
cockpit-image-builder (Red Hat package) - update to 94.3-1.el10_2
cockpit-machines - update to 249.1-150300.5.3.1
cockpit-debugsource - update to 251.3-150300.6.6.1
cockpit - update to 251.3-150300.6.6.1
cockpit-debuginfo - update to 251.3-150300.6.6.1
cockpit-ws - update to 251.3-150300.6.6.1
cockpit-system - update to 251.3-150300.6.6.1
cockpit-bridge - update to 251.3-150300.6.6.1
cockpit-bridge-debuginfo - update to 251.3-150300.6.6.1
cockpit-ws-debuginfo - update to 251.3-150300.6.6.1

External References

Related Security Bulletins