CVE-2026-2950 | Lodash up to 4.17.x _.unset/_.omit prototype pollution (GHSA-xxjr-mmjv-4gpg)
A vulnerability labeled as critical has been found in Lodash up to 4.17.x. This issue affects the function _.unset/_.omit. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability is registered as CVE-2026-2950. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.