← back
CVE-2021-23337high

Command Injection

41Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.2epss 21%
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
Affected products
n/a · Lodash