npm package report

Is lodash safe?

8 known vulnerabilities, worst severity CRITICAL.

// advisories

fig. 01, known advisories affecting lodash

GHSA-f23m-r3pf-42rhMODERATE2026-04-01

Affected >=4.0.0, <4.17.23 · fixed in 4.18.0

GHSANVDMITRE

GHSA-xxjr-mmjv-4gpgMODERATE2026-01-21

Affected >=4.0.0, <4.18.0 · fixed in 4.17.23

GHSANVDMITRE

GHSA-35jh-r3h4-6jhmHIGH2021-05-06

Affected >=4.0.0, <4.18.0 · fixed in 4.17.21

GHSANVDMITRE

GHSA-r5fr-rjxr-66jcHIGH2026-04-01

Affected >=0, <4.17.21 · fixed in 4.18.0

GHSANVDMITRE


// ai model usage

Model usage is tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


checked 2026-09-21 22:27 UTC · most recent advisory 2026-04-01 · updated continuously from NVD, GHSA, OSV and CNA feeds

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is lodash safe? npm package security report | CyberXYZ