Underscorejs Underscore vulnerabilities
2 known vulnerabilities affecting underscorejs/underscore.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-27601HIGHCVSS 8.2fixed in 1.13.82026-03-03
CVE-2026-27601 [HIGH] CWE-770 CVE-2026-27601: Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastr
ghsanvdosv
CVE-2021-23358HIGHCVSS 7.2≥ 1.3.2, < 1.12.1≥ 1.13.0-0, < 1.13.0-2+4 more2021-03-29
CVE-2021-23358 [HIGH] CWE-94 CVE-2021-23358: The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerabl
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
cvelistv5ghsanvdosv