| CVE ID | Published | Description | Score | Severity |
|---|---|---|---|---|
| Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | 7.2 |
High |
||
| Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. | 5.3 |
Medium |
||
| Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | 7.4 |
High |