/Vulnerability Library

Lodash Template - Server-Side Template Injection (RCE)

CVE-2021-23337
Verified

Description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Severity

High

CVSS Score

7.2

Exploit Probability

21%

Affected Product

lodash

Published Date

April 7, 2026

Template Author

dhiyaneshdk

CVE-2021-23337.yaml
7.2Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-23337
CWE ID:
cwe-94

References

https://nvd.nist.gov/vuln/detail/CVE-2021-23337https://security.snyk.io/vuln/SNYK-JS-LODASH-1040724https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1chttps://github.com/advisories/GHSA-35jh-r3h4-6jhm

Remediation Steps

Update to version 4.17.21 or later.