← back
CVE-2019-10744

CVE-2019-10744

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 5.0%
exploitation probability
5.0%top 8% of all CVEs
observed exploitation
nono source reports it
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Affected products
Snyk · lodash