Prototype Pollution in lodash versions <=4.7.11
Open
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 121
- Forks
- 15
- Avg merge
- 17h 22m
- Merged PRs (30d)
- 3
Description

As there s a vulnerability in the lodash version used by Netflix/nerror, could you please help us by updating to latest version of lodash.
We are blocked due to this vulnerability in lodash version.
Thanks
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the dependency manifest and checking which lodash version nerror currently uses. Review the vulnerability affecting versions <=4.7.11, update the dependency to a supported version, and run the repository's existing tests to confirm error handling still works.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100