Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| lodash(npm) | 0 | 4.17.21 | N/A |
| lodash-es(npm) | 0 | 4.17.21 | N/A |
| lodash.template(npm) | 0 | N/A | N/A |
| lodash-template(npm) | 0 | N/A | N/A |
| lodash-rails(RubyGems) | 0 | 4.17.21 | N/A |
CVSS Metrics