8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether lodash-es is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.2
CVE-2021-23337
Command Injection in lodash
HIGH 8.1
CVE-2021-23337
lodash vulnerable to Code Injection via `_.template` imports key names
MEDIUM 6.5
CVE-2025-13465
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
MEDIUM 6.5
CVE-2025-13465
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
CRITICAL 9.1
CVE-2019-10744
Prototype Pollution in lodash
MEDIUM 6.5
CVE-2019-1010266
Regular Expression Denial of Service (ReDoS) in lodash
MEDIUM 5.3
CVE-2020-28500
Regular Expression Denial of Service (ReDoS) in lodash
HIGH 7.4
CVE-2020-8203
Prototype Pollution in lodash
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes