Overview
Versions of lodash before 4.17.5 are vulnerable to prototype pollution.
The vulnerable functions are defaultsDeep, merge, and mergeWith which allow a malicious user to modify the prototype of Object via {constructor: {prototype: {...}}} causing the addition or modification of an existing property that will exist on all objects.
From https://www.npmjs.com/advisories/782:
Overview Versions of lodash before 4.17.5 are vulnerable to prototype pollution.
The vulnerable functions are
defaultsDeep
,merge
, andmergeWith
which allow a malicious user to modify the prototype ofObject
via{constructor: {prototype: {...}}}
causing the addition or modification of an existing property that will exist on all objects.Remediation Update to version 4.17.11 or later.
Resources HackerOne Report