CVE-2026-4800 | Lodash up to 4.17.x Parameter Function options.imports code injection (GHSA-35jh-r3h4-6jhm / Nessus ID 304625)
A vulnerability was found in Lodash up to 4.17.x and classified as critical. Affected by this issue is the function Function of the component Parameter Handler. The manipulation of the argument options.imports results in code injection.
This vulnerability was named CVE-2026-4800. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.