Code Injection in Lodash - CVE-2026-4800
Published: April 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in _.template when processing untrusted options.imports key names. A remote attacker can supply crafted imports key names to execute arbitrary code.
Code execution occurs at template compilation time. If Object.prototype has been polluted by another vector, inherited polluted keys can also be copied into the imports object and passed to Function().
Affected software
Storage Sentinel Anomaly Scan Engine
Storage Defender Copy Data Management
Storage Fusion Data Foundation
Maximo Application Suite - Monitor Component
Rational Performance Tester
DevOps Test Performance
InfoSphere Optim Archive Viewer
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Scheduler Optimizer
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
Jira Service Management Data Center
IBM Tivoli Netcool/OMNIbus WebGUI
Confluence Data Center
Jira Software Data Center
Bamboo Data Center
IBM Business Automation Workflow
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Ubuntu
IBM App Connect Enterprise
IBM Security SOAR
pcs (Red Hat package)
pcs
python-jupytext
yarnpkg
node-lodash (Ubuntu package)
pgadmin4
nextcloud
cockpit-image-builder (Red Hat package)
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
JBoss Data Grid
How to mitigate CVE-2026-4800
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
Storage Defender Copy Data Management - update to 2.3.0.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
Jira Service Management Data Center - addressed in versions 10.3.24, 11.3.7
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Maximo Application Suite - Monitor Component - addressed in versions 8.10.29, 8.11.27, 9.0.19, 9.1.9
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
Bamboo Data Center - addressed in versions 10.2.21, 12.1.8
DevOps Test Performance - update to 11.0.8
InfoSphere Optim Archive Viewer - update to 11.7.0.14
IBM App Connect Enterprise - addressed in versions 12.0.12.25, 13.0.7.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Security SOAR - update to 51.0.10.0
pcs (Red Hat package) - addressed in versions 0.10.12-6.el8_6.13, 0.10.15-4.el8_8.11, 0.11.1-10.el9_0.11, 0.11.4-7.el9_2.8, 0.11.7-2.el9_4.7, 0.11.9-2.el9_6.4, 0.11.10-1.el9_7.3, 0.12.0-3.el10_0.5, 0.12.1-1.el10_1.3
pcs - addressed in versions 0.12.2-2.fc43, 0.12.2-2.fc44, 0.12.2-2.fc45
python-jupytext - addressed in versions 1.19.1-4.fc42, 1.19.1-4.fc43, 1.19.1-4.fc44
yarnpkg - addressed in versions 1.22.22-18.el9, 1.22.22-18.el10_3, 1.22.22-18.fc42, 1.22.22-18.fc43, 1.22.22-18.fc44
node-lodash (Ubuntu package) - addressed in versions 2.4.1+dfsg-3ubuntu0.1~esm1, 4.17.4+dfsg-1ubuntu0.1~esm1, 4.17.15+dfsg-2ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1, 4.17.23+dfsg-1ubuntu0.1~esm1
Red Hat OpenShift Container Platform - addressed in versions 4.16.66, 4.17.55, 4.19.40, 4.20.30, 4.21.24, 4.22.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
JBoss Data Grid - update to 8.6.1
pgadmin4 - addressed in versions 9.14-1.fc42, 9.14-1.fc43, 9.14-1.fc44, 9.14-2.fc42, 9.14-2.fc43, 9.14-2.fc44, 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
cockpit-image-builder (Red Hat package) - update to 94.3-1.el10_2
External References
Related Security Bulletins
- Multiple vulnerabilities in Lodash
- Fedora 43 update for yarnpkg
- Fedora EPEL 9 update for yarnpkg
- Fedora 42 update for yarnpkg
- Fedora EPEL 10.3 update for yarnpkg
- Fedora 44 update for yarnpkg
- Fedora 42 update for pgadmin4
- Fedora 43 update for pgadmin4
- Fedora 44 update for pgadmin4
- Fedora 44 update for pgadmin4
- Fedora 43 update for pgadmin4
- Fedora 42 update for pgadmin4
- Multiple vulnerabilities in IBM DevOps Test Performance
- Red Hat Enterprise Linux 9 update for pcs
- Red Hat Enterprise Linux 10 update for pcs
- Multiple vulnerabilities in IBM App Connect Enterprise
- Red Hat Enterprise Linux 9 update for pcs
- Red Hat Enterprise Linux 9 update for pcs
- Red Hat Enterprise Linux 10 update for pcs
- Red Hat Enterprise Linux 9 update for pcs
- Red Hat Enterprise Linux 8 update for pcs
- Red Hat Enterprise Linux 8 update for pcs
- Red Hat Enterprise Linux 9 update for pcs
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in IBM Storage Defender Copy Data Management
- Multiple vulnerabilities in IBM Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM Maximo Scheduler Optimizer
- Fedora 43 update for pcs
- Fedora 44 update for pcs
- Fedora 45 update for pcs
- Fedora 43 update for pgadmin4
- Fedora 42 update for pgadmin4
- Fedora 44 update for pgadmin4
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus_GUI
- Multiple vulnerabilities in IBM Security SOAR
- Multiple vulnerabilities in IBM InfoSphere Optim Archive Viewer
- Red Hat Enterprise Linux 10 update for cockpit-image-builder
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Discovery Cartridge
- Ubuntu update for node-lodash
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora EPEL 10.3 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora 42 update for nextcloud
- Multiple vulnerabilities in JBoss Data Grid 8.6
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in IBM Fusion Data Foundation
- Fedora 44 update for python-jupytext
- Fedora 43 update for python-jupytext
- Fedora 42 update for python-jupytext
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center