CVE-2021-23337

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

  • Published Feb 15, 2021
  • CVSS 7.2 high
  • 21.3% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available
  • A fix is available

Affected software

In the news

CVE-2021-23337 at the National Vulnerability Database