Skip to main content

CVE-2025-13465

CVE Details

Visit the official vulnerability details page for CVE-2025-13465 to learn more.

Initial Publication

01/21/2026

Last Update

01/21/2026

Third Party Dependency

lodash

NIST CVE Summary

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.

The issue permits deletion of properties but does not allow overwriting their original behavior.

This issue is patched on 4.17.23

CVE Severity

0

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Received

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.6.0⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.