From 3cd591596412ca4667911f8478c570e241694521 Mon Sep 17 00:00:00 2001 From: maximthomas Date: Tue, 27 Jan 2026 10:57:00 +0300 Subject: [PATCH 1/2] CVE-2025-13465 Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions --- openig-ui/package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openig-ui/package.json b/openig-ui/package.json index c548a648..9a8ed0a5 100644 --- a/openig-ui/package.json +++ b/openig-ui/package.json @@ -21,7 +21,7 @@ "grunt-serve": "0.1.6", "grunt-sync": "0.8.1", "less-plugin-clean-css": "1.5.1", - "lodash": ">=4.17.21", + "lodash": ">=4.17.23", "requirejs": "2.3.7", "es5-ext": "0.10.53" }, From 6a3a40fb6e1e633cbac97b6e0e3ccd1b2b1261f9 Mon Sep 17 00:00:00 2001 From: Maxim Thomas Date: Tue, 27 Jan 2026 12:54:52 +0300 Subject: [PATCH 2/2] Update lodash version to 4.17.23 --- openig-ui/package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openig-ui/package.json b/openig-ui/package.json index 9a8ed0a5..d2ee35f7 100644 --- a/openig-ui/package.json +++ b/openig-ui/package.json @@ -34,6 +34,6 @@ "fresh": ">=0.5.2", "send": ">=0.19.0", "dot": ">=1.1.3", - "lodash": ">=4.17.21" + "lodash": ">=4.17.23" } }