Prototype pollution in Lodash - CVE-2026-2950

 

Prototype pollution in Lodash - CVE-2026-2950

Published: April 10, 2026


Vulnerability identifier: #VU125804
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2950
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify object prototype attributes.

The vulnerability exists due to improper control of object prototype modification in _.unset and _.omit when processing array-wrapped path segments. A remote attacker can pass crafted path segments to modify object prototype attributes.

The bypass affects checks that only guard against string key members. The issue permits deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype, but does not allow overwriting their original behavior.


Affected software

Lodash
Storage Sentinel Anomaly Scan Engine
Storage Defender Copy Data Management
Storage Fusion Data Foundation
Maximo Application Suite - Monitor Component
Rational Performance Tester
DevOps Test Performance
InfoSphere Optim Archive Viewer
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Scheduler Optimizer
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Business Automation Workflow
IBM App Connect Enterprise
Ubuntu
IBM Security SOAR
node-lodash (Ubuntu package)

How to mitigate CVE-2026-2950

Install security update from vendor's website.

Lodash - update to 4.18.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
Storage Defender Copy Data Management - update to 2.3.0.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
Maximo Application Suite - Monitor Component - addressed in versions 8.10.29, 8.11.27, 9.0.19, 9.1.9
DevOps Test Performance - update to 11.0.8
InfoSphere Optim Archive Viewer - update to 11.7.0.14
IBM App Connect Enterprise - addressed in versions 12.0.12.25, 13.0.7.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Security SOAR - update to 51.0.10.0
node-lodash (Ubuntu package) - addressed in versions 2.4.1+dfsg-3ubuntu0.1~esm1, 4.17.4+dfsg-1ubuntu0.1~esm1, 4.17.15+dfsg-2ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1, 4.17.23+dfsg-1ubuntu0.1~esm1
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11

External References

Related Security Bulletins