Code Injection in Lodash - CVE-2026-4800

 

Code Injection in Lodash - CVE-2026-4800

Published: April 10, 2026


Vulnerability identifier: #VU125803
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4800
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in _.template when processing untrusted options.imports key names. A remote attacker can supply crafted imports key names to execute arbitrary code.

Code execution occurs at template compilation time. If Object.prototype has been polluted by another vector, inherited polluted keys can also be copied into the imports object and passed to Function().


Affected software

Lodash
Storage Sentinel Anomaly Scan Engine
Storage Defender Copy Data Management
Storage Fusion Data Foundation
Maximo Application Suite - Monitor Component
Rational Performance Tester
DevOps Test Performance
InfoSphere Optim Archive Viewer
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Scheduler Optimizer
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
Jira Service Management Data Center
IBM Tivoli Netcool/OMNIbus WebGUI
Confluence Data Center
Jira Software Data Center
Bamboo Data Center
IBM Business Automation Workflow
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Ubuntu
IBM App Connect Enterprise
IBM Security SOAR
pcs (Red Hat package)
pcs
python-jupytext
yarnpkg
node-lodash (Ubuntu package)
pgadmin4
nextcloud
cockpit-image-builder (Red Hat package)
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
JBoss Data Grid

How to mitigate CVE-2026-4800

Install security update from vendor's website.

Lodash - update to 4.18.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
Storage Defender Copy Data Management - update to 2.3.0.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
Jira Service Management Data Center - addressed in versions 10.3.24, 11.3.7
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Maximo Application Suite - Monitor Component - addressed in versions 8.10.29, 8.11.27, 9.0.19, 9.1.9
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
Bamboo Data Center - addressed in versions 10.2.21, 12.1.8
DevOps Test Performance - update to 11.0.8
InfoSphere Optim Archive Viewer - update to 11.7.0.14
IBM App Connect Enterprise - addressed in versions 12.0.12.25, 13.0.7.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Security SOAR - update to 51.0.10.0
pcs (Red Hat package) - addressed in versions 0.10.12-6.el8_6.13, 0.10.15-4.el8_8.11, 0.11.1-10.el9_0.11, 0.11.4-7.el9_2.8, 0.11.7-2.el9_4.7, 0.11.9-2.el9_6.4, 0.11.10-1.el9_7.3, 0.12.0-3.el10_0.5, 0.12.1-1.el10_1.3
pcs - addressed in versions 0.12.2-2.fc43, 0.12.2-2.fc44, 0.12.2-2.fc45
python-jupytext - addressed in versions 1.19.1-4.fc42, 1.19.1-4.fc43, 1.19.1-4.fc44
yarnpkg - addressed in versions 1.22.22-18.el9, 1.22.22-18.el10_3, 1.22.22-18.fc42, 1.22.22-18.fc43, 1.22.22-18.fc44
node-lodash (Ubuntu package) - addressed in versions 2.4.1+dfsg-3ubuntu0.1~esm1, 4.17.4+dfsg-1ubuntu0.1~esm1, 4.17.15+dfsg-2ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1, 4.17.23+dfsg-1ubuntu0.1~esm1
Red Hat OpenShift Container Platform - addressed in versions 4.16.66, 4.17.55, 4.19.40, 4.20.30, 4.21.24, 4.22.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
JBoss Data Grid - update to 8.6.1
pgadmin4 - addressed in versions 9.14-1.fc42, 9.14-1.fc43, 9.14-1.fc44, 9.14-2.fc42, 9.14-2.fc43, 9.14-2.fc44, 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
cockpit-image-builder (Red Hat package) - update to 94.3-1.el10_2

External References

Related Security Bulletins