CVE-2019-10744

9.1
CRITICALCVSS v3.1 Base Score
5.01%
LOW RiskEPSS (92nd percentile)

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Published: 7/26/2019
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CVSS v2 Score

6.4

AV:N/AC:L/Au:N/C:N/I:P/A:P

EPSS Score (Exploitation Probability)

5.01%LOW Exploitation Risk
92nd percentile

This vulnerability has a 5.01% probability of being exploited in the next 30 days, ranking higher than 92% of all scored CVEs.

CWE Classification

Advertisement