An open index of dependabot pull requests across open source projects.

Command Injection in lodash

GHSA-35jh-r3h4-6jhm CVE-2021-23337
Description:

lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Affected Packages
Ecosystem Package Vulnerable Versions Patched Version
npm lodash-es < 4.17.21
4.17.21
npm lodash < 4.17.21
4.17.21
Related Dependabot Pull Requests
Bump lodash from 4.17.21 to 4.18.1
Closed about 8 hours ago
Tina2010/myFlix-Client #9
npm:lodash
Tina2010
build(deps): bump the npm_and_yarn group across 1 directory with 10 updates
Open about 9 hours ago
gitroomhq/postiz-app #1536
npm:axios npm:vite +7 more
gitroomhq
build(deps): bump the npm_and_yarn group across 1 directory with 7 updates
Closed about 13 hours ago
Milky-Way-Cookie/autograd-engine #12
npm:vite npm:rollup +5 more
Milky-Way-Cookie
chore(deps): bump lodash from 4.17.23 to 4.18.1
Open about 16 hours ago
bronsonacoutts/MyTemplates #29
npm:lodash
bronsonacoutts
Bump the production-dependencies group with 4 updates
Closed about 16 hours ago
Sammons/certbot-cloudflare-wrapper #35
npm:express npm:lodash +2 more
Sammons
chore(deps-dev): bump lodash from 4.17.23 to 4.18.1 in /html/themes/custom/common_design_subtheme
Closed about 16 hours ago
UN-OCHA/common-design-site #633
npm:lodash
UN-OCHA
Bump lodash from 4.17.21 to 4.18.1
Open about 17 hours ago
Mordi490/lineup-larry #39
npm:lodash
Mordi490
chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates
Open about 18 hours ago
drewjocham/arguskube #112
npm:vite npm:lodash
drewjocham
Bump the npm_and_yarn group across 2 directories with 7 updates
Open about 18 hours ago
nilhemdot/openwolf #1
npm:vite npm:lodash +3 more
nilhemdot
chore(deps): bump the npm_and_yarn group across 4 directories with 10 updates
Open about 21 hours ago
CHENY260/onyx #1
npm:vite npm:next +4 more
CHENY260
Bump the npm_and_yarn group across 1 directory with 9 updates
Open about 22 hours ago
Googleclaude/react-router-starter-template-1 #1
npm:react-router npm:vite +7 more
Googleclaude
Bump lodash from 4.17.21 to 4.18.1
Open 1 day ago
DougMackenzie/power-insight #6
npm:lodash
DougMackenzie
Bump the npm_and_yarn group across 7 directories with 10 updates
Open 1 day ago
balajirajput96/onnxruntime #42
npm:follow-redirects npm:lodash +3 more
balajirajput96
Bump the npm_and_yarn group across 1 directory with 5 updates
Open 1 day ago
advayc/sitemaker #11
npm:next npm:postcss +3 more
advayc
Bump lodash from 4.17.20 to 4.18.1 in /javascript
Open 1 day ago
fullerrc/dependabot-demo #6
npm:lodash
fullerrc
Bump lodash from 4.17.21 to 4.18.1
Open 2 days ago
gtibrett/effone-hub #26
npm:lodash
gtibrett
Bump lodash from 4.17.21 to 4.18.1
Closed 2 days ago
deflis/ranking.riel.live #66
npm:lodash
deflis
Bump lodash-es from 4.17.21 to 4.18.1 in /js
Open 2 days ago
imantubex-create/keycloak__keycloak__prixai__PR38446__20260516 #51
npm:lodash-es
imantubex-create
Bump lodash-es from 4.17.21 to 4.18.1 in /js
Open 2 days ago
imantubex-create/keycloak__keycloak__prixai__PR36880__20260516 #60
npm:lodash-es
imantubex-create
Bump lodash-es from 4.17.21 to 4.18.1 in /js
Open 2 days ago
imantubex-create/keycloak__keycloak__prixai__PR37038__20260516 #47
npm:lodash-es
imantubex-create
Bump the npm_and_yarn group across 2 directories with 17 updates
Closed 2 days ago
ZAK123DSFDF/refearnapp #27
npm:axios npm:next +3 more
ZAK123DSFDF
Bump lodash from 4.17.21 to 4.18.1
Closed 2 days ago
michal-cecko/sw-kysuce-web #3
npm:lodash
michal-cecko
chore(deps): bump the npm_and_yarn group across 1 directory with 7 updates
Closed 2 days ago
marceljk/pv_tracker #32
npm:vite npm:serialize-javascript +5 more
marceljk
chore(deps): bump the npm_and_yarn group across 12 directories with 10 updates
Open 2 days ago
balajirajput96/openai-node #44
npm:axios npm:lodash +4 more
balajirajput96
Bump lodash from 4.17.21 to 4.18.1 in /samples/tab-stage-view/nodejs
Closed 2 days ago
shaneslo/Microsoft-Teams-Samples #4
npm:lodash
shaneslo
Bump lodash from 4.17.15 to 4.18.1
Open 2 days ago
bhargava16623/dependabot-alternatives-test #10
npm:lodash
bhargava16623
Bump the npm_and_yarn group across 1 directory with 7 updates
Open 2 days ago
OsoPanda1/utamv-elite-masterclass #6
npm:vite npm:rollup +5 more
OsoPanda1
Bump the npm_and_yarn group across 1 directory with 13 updates
Open 2 days ago
jamesbroadmore/carterscare-v2.1 #1
npm:react-router npm:vite +10 more
jamesbroadmore
Bump lodash from 4.17.21 to 4.18.1
Open 3 days ago
shogo82148/rfc-translated-ja #127
npm:lodash
shogo82148
Bump the npm_and_yarn group across 16 directories with 21 updates
Open 3 days ago
AKJUS/todomvc #27
npm:postcss npm:follow-redirects +12 more
AKJUS
Bump lodash from 4.17.4 to 4.18.1
Closed 3 days ago
1995parham/react-canvas-gauges #7
npm:lodash
1995parham
ci: bump the npm_and_yarn group across 2 directories with 5 updates
Open 3 days ago
jadenblack/coder #17
npm:yaml npm:minimatch +3 more
jadenblack
chore(deps): bump the npm_and_yarn group across 2 directories with 16 updates
Open 3 days ago
servrox-solutions/punktaro-app #6
npm:@babel/helpers npm:cross-spawn +12 more
servrox-solutions
chore(deps): Bump the npm_and_yarn group across 1 directory with 16 updates
Closed 3 days ago
robertcdawson/coronavirus-us-county-tracker #28
npm:axios npm:yaml +10 more
robertcdawson
Bump the npm_and_yarn group across 1 directory with 17 updates
Closed 3 days ago
shsunmoonlee/CryptoCurrencyData #1
npm:axios npm:express +10 more
shsunmoonlee
chore(deps): bump lodash-es from 4.17.21 to 4.18.1 in /docs
Closed 3 days ago
samber/lo #885
npm:lodash-es
samber
chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates
Open 3 days ago
kinde-oss/js-utils #233
npm:postcss npm:minimatch +3 more
kinde-oss
Bump lodash, grunt-legacy-log and grunt-legacy-util
Open 3 days ago
wp-media/imagify-plugin #1049
npm:grunt-legacy-util npm:lodash, grunt-legacy-log
wp-media
Bump lodash from 4.17.21 to 4.18.1
Open 3 days ago
d33naz/shesnotcrazybook #13
npm:lodash
d33naz
Bump the npm_and_yarn group across 1 directory with 14 updates
Open 3 days ago
stupidkubik/kanban-board-app #10
npm:vite npm:next +12 more
stupidkubik
Bump the npm_and_yarn group across 1 directory with 9 updates
Closed 3 days ago
stefanteitge/rc-cloud #21
npm:follow-redirects npm:lodash +7 more
stefanteitge
chore(deps): bump the npm_and_yarn group across 1 directory with 12 updates
Open 3 days ago
xiaomizhoubaobei/302_image_toolbox #25
npm:cross-spawn npm:nanoid +10 more
xiaomizhoubaobei
chore(deps): bump the npm_and_yarn group across 4 directories with 14 updates
Open 3 days ago
Dargon789/safe-apps-sdk #199
npm:lodash npm:node-forge +3 more
Dargon789
Bump lodash from 4.17.20 to 4.18.1 in /javascript
Closed 3 days ago
e5pe0n/demo #5
npm:lodash
e5pe0n
Bump lodash from 4.17.21 to 4.18.1
Open 4 days ago
FlyteWizard/csc-seng-heat-outlines #37
npm:lodash
FlyteWizard
chore(deps): bump the npm_and_yarn group across 6 directories with 20 updates
Open 4 days ago
loveyou001/wizard #19
npm:axios npm:follow-redirects +5 more
loveyou001
Bump lodash-es from 4.17.23 to 4.18.1
Open 4 days ago
alveusgg/alveusgg #2094
npm:lodash-es
alveusgg
Bump the npm_and_yarn group across 12 directories with 6 updates
Closed 4 days ago
gagan0123/jetpack #19
npm:undici npm:lodash +2 more
gagan0123
chore(deps): bump lodash-es from 4.17.23 to 4.18.1
Open 4 days ago
rebekah-create/inbox-zero-rebekah #25
npm:lodash-es
rebekah-create
Bump the npm_and_yarn group across 1 directory with 8 updates
Closed 4 days ago
fharisorg/repo #1
npm:vite npm:postcss +5 more
fharisorg
Advisory Details
Published: May 06, 2021 about 5 years ago
Updated: May 18, 2026 about 16 hours ago
CVSS Score: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS: 3.29% 87th percentile
Source: Github
Classification: GENERAL
UUID: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTM1amgtcjNoNC02amht
PR Statistics
PR Status
Open 2735 (57.9%)
Merged 2 (0.0%)
Closed 1983 (42.0%)
Update Types
Major 1408 (7.5%)
Minor 10379 (55.6%)
Patch 6678 (35.8%)