You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5c19af4
Browse filesBrowse the repository at this point in the historyBrowse files
* Resolve CVE-2026-4800 by bumping lodash and lodash-es to ^4.18.0
Details:
The fix for CVE-2021-23337 added validation for the variable option in
_.template but did not apply the same validation to options.imports key
names. Both paths flow into the same Function() constructor sink. When
an application passes untrusted input as options.imports key names, an
attacker can inject default-parameter expressions that execute arbitrary
code at template compilation time. Additionally, _.template uses
assignInWith to merge imports, which enumerates inherited properties
via for..in. If Object.prototype has been polluted by any other vector,
the polluted keys are copied into the imports object and passed to
Function().
Impact:
When an application passes untrusted input as options.imports key names
to _.template, an attacker can inject default-parameter expressions
that execute arbitrary code at template compilation time. Additionally,
prototype pollution can be exploited via assignInWith to inject keys
into the Function() constructor.
Fix:
Bumped lodash and lodash-es resolutions to ^4.18.0 in package.json.
Version 4.18.0 validates importsKeys against reForbiddenIdentifierChars
and replaces assignInWith with assignWith when merging imports.
Signed-off-by: KashKondaka <37753523+KashKondaka@users.noreply.github.com>
* Fixed CI workflows to use correct OSD branch.
Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
* Updated snapshots.
Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
* Consolidated CVE fixes: added minimatch, yaml, and picomatch resolutions.
Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
---------
Signed-off-by: KashKondaka <37753523+KashKondaka@users.noreply.github.com>
Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
Co-authored-by: Thomas Hurney <hurneyt@amazon.com>
0 commit comments