π Security Remediation Task: HIGH CVSS Exploitable CVE in Code Repository β lodash/lodash-es + CVE-2026-4800 (Γ2 packages)
For AI Agent: This issue is auto-generated from Wiz. All information needed to remediate is below. Do not ask for clarification. Weigh the exploitation signals (EPSS / public exploit / PoC) and actual code reachability before acting β not every listed finding must become a code change: deferring a genuinely unreachable, low-signal, non-critical finding (with a recorded reason) is a valid disposition. Never claim to fix a CVE the resource is not actually exposed to.
π Resource Context
π€ Green Agent Analysis
No Green Agent analysis available for this issue.
π Findings (Medium+ Β· Sorted by Exploitation Likelihood)
Finding 1: CVE-2022-46175 β HIGH (json5 v1.0.1, Γ2 paths)
| Field |
Value |
| Finding IDs |
345d293f-706d-5946-90d1-38b375ee8c3f (v1.0.1 β fix 1.0.2), cdcff653-7701-5740-9b0e-265b16338a7f (v1.0.1 β fix 1.0.2), 73842648-2925-5346-8d1f-674fbcea154c (v1.0.1 β fix 2.2.2), b3d7dfed-8e55-544f-9e9c-44c4e49bb2b1 (v2.2.1 β fix 2.2.2) |
| CVE / Reference |
CVE-2022-46175 / GHSA-9c47-m6qq-7p4h |
| Severity (Wiz) |
HIGH (CVSS 8.8) |
| Exploitation signals |
EPSS 9.2% Β· Public Exploit Yes Β· Public PoC Yes |
| Reachability |
NOT VERIFIED β agent must assess |
| Affected Component |
json5 v1.0.1 and v2.2.1, /yarn.lock |
| Fixed In Version |
v1.0.2 (for 1.x branch), v2.2.2 (for 2.x branch) |
| Introduced Via |
transitive β introducing package not in Wiz data; agent must trace with yarn why json5 |
| File Path / Location |
/yarn.lock (lines 1926, 1933) |
Description:
The JSON5.parse() method in json5 versions β€ 1.0.1 and β€ 2.2.1 does not restrict parsing of keys named __proto__, enabling prototype pollution on the returned object. An attacker who can supply a crafted JSON5 string to a code path using JSON5.parse() can set arbitrary inherited properties on the parsed object. Depending on how the application uses that object, this may lead to denial of service, XSS, privilege escalation, or in extreme cases remote code execution. The EPSS score of 9.2% and confirmed public exploit/PoC make this a credible risk where the parse method is reachable with untrusted input.
AI Analysis Summary:
No reachability analysis available β the agent must assess reachability itself; weigh the exploitation signals above (EPSS 9.2%, public exploit confirmed) and do NOT assume exploitable without tracing call sites.
Bump json5 to β₯ 1.0.2 (for 1.x consumers) and β₯ 2.2.2 (for 2.x consumers) in /yarn.lock and regenerate the lockfile with yarn upgrade json5; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.
Finding 2: CVE-2024-4068 β HIGH (braces v3.0.2, Γ2 paths)
| Field |
Value |
| Finding IDs |
77026867-ca80-5a43-a8db-ed715bc11130, 3d1578ce-23eb-581e-9d58-1458d48d616b |
| CVE / Reference |
CVE-2024-4068 / GHSA-grv7-fg5c-xmjg |
| Severity (Wiz) |
HIGH (CVSS 7.5) |
| Exploitation signals |
EPSS 1.5% Β· Public Exploit Yes Β· Public PoC Yes |
| Reachability |
NOT VERIFIED β agent must assess |
| Affected Component |
braces v3.0.2, /yarn.lock (line 592) |
| Fixed In Version |
v3.0.3 |
| Introduced Via |
transitive β introducing package not in Wiz data; agent must trace with yarn why braces |
| File Path / Location |
/yarn.lock |
Description:
The braces NPM package versions prior to 3.0.3 fail to limit the number of characters processed by the parser. If a malicious user supplies "imbalanced braces" as input, lib/parse.js enters an infinite loop that continuously allocates heap memory without releasing it, eventually exhausting the JavaScript heap limit and crashing the Node.js process. This is a denial-of-service vulnerability. A public exploit exists (VulnCheck / upstream PR). Trigger requires the attacker to control input passed through a braces-consuming code path (commonly via glob/minimatch patterns).
AI Analysis Summary:
No reachability analysis available β the agent must assess reachability itself; weigh the exploitation signals above (public exploit confirmed, EPSS 1.5%) and do NOT assume exploitable without tracing call sites.
Bump braces to β₯ 3.0.3 in /yarn.lock using yarn upgrade braces; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.
Finding 3: CVE-2026-4800 β CRITICAL (lodash v4.17.21)
| Field |
Value |
| Finding IDs |
c54087ec-2634-587f-9c06-ba77e0f6ec11, 63781bc8-f278-50c5-9cc3-25b5044d6786 |
| CVE / Reference |
CVE-2026-4800 / GHSA-r5fr-rjxr-66jc |
| Severity (Wiz) |
CRITICAL (CVSS 9.8) |
| Exploitation signals |
EPSS 2.6% Β· Public Exploit Yes Β· Public PoC Yes |
| Reachability |
NOT VERIFIED β agent must assess (Wiz Threat Research note: initial access potential overridden to FALSE; only exploitable under specific conditions) |
| Affected Component |
lodash v4.17.21, /yarn.lock (line 2062) |
| Fixed In Version |
v4.18.0 |
| Introduced Via |
transitive β introducing package not in Wiz data; agent must trace with yarn why lodash |
| File Path / Location |
/yarn.lock |
Description:
The fix for CVE-2021-23337 added validation for _.template's variable option but failed to apply the same validation to options.imports key names. Both paths feed into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary JavaScript at template compilation time. Additionally, _.template uses assignInWith (enumerates inherited properties via for..in), meaning a prior prototype pollution can cause polluted keys to flow into Function(). Wiz Threat Research has flagged that initial access potential is overridden to FALSE because exploitation requires specific application conditions (untrusted input reaching options.imports). The CVSS score of 9.8 is high, but actual risk depends heavily on code reachability.
AI Analysis Summary:
Wiz Threat Research has overridden initial access potential to FALSE for CVE-2026-4800 since the vulnerability is only exploitable under specific conditions (untrusted input passed as options.imports key names to _.template). The agent must assess whether the application passes user-controlled data to this code path before treating this as critical priority. A public PoC exists (VulnCheck).
Bump lodash to β₯ 4.18.0 in /yarn.lock using yarn upgrade lodash; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals and reachability assessment.
Finding 4: CVE-2026-4800 β CRITICAL (lodash-es v4.17.21)
| Field |
Value |
| Finding IDs |
b47ac0cb-b8f5-505e-94c1-8feb5de6e33e, 675f04b4-3d37-51a3-9f45-3f3d813e5ad0 |
| CVE / Reference |
CVE-2026-4800 / GHSA-r5fr-rjxr-66jc |
| Severity (Wiz) |
CRITICAL (CVSS 9.8) |
| Exploitation signals |
EPSS 2.6% Β· Public Exploit Yes Β· Public PoC Yes |
| Reachability |
NOT VERIFIED β agent must assess (Wiz Threat Research note: initial access potential overridden to FALSE; only exploitable under specific conditions) |
| Affected Component |
lodash-es v4.17.21, /yarn.lock (line 2017) |
| Fixed In Version |
v4.18.0 |
| Introduced Via |
transitive β introducing package not in Wiz data; agent must trace with yarn why lodash-es |
| File Path / Location |
/yarn.lock |
Description:
Same vulnerability class as Finding 3 (CVE-2026-4800) but affecting the ESM variant lodash-es. The _.template function's options.imports key names are passed unsanitized into a Function() constructor, enabling code injection when untrusted input reaches that path. Additionally assignInWith enumerates inherited properties, creating a prototype-pollution amplification path. Wiz Threat Research has overridden initial access potential to FALSE. The CVSS of 9.8 is critical on paper; actual exploitability depends on whether application code routes untrusted data into _.template imports.
AI Analysis Summary:
Wiz Threat Research has overridden initial access potential to FALSE for CVE-2026-4800 on lodash-es since the vulnerability is only exploitable under specific conditions. Same guidance as Finding 3. Agent must trace lodash-es usage with yarn why lodash-es and verify call sites before prioritising.
Bump lodash-es to β₯ 4.18.0 in /yarn.lock using yarn upgrade lodash-es; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals and reachability assessment.
Finding 5: CVE-2022-25883 β HIGH (semver, Γ5 paths)
| Field |
Value |
| Finding IDs |
e1893cec-af83-552b-a9fb-ec7822bf00c5 (v5.7.1 β 5.7.2), eab16ed9-de63-5ba7-b535-fd20903c850b (v7.3.8 β 7.5.2), d1e841ed-5f79-53f7-94fb-3a0bfb00ed75 (v6.3.0 β 6.3.1), e4ecd1cd-4712-50d7-b7f3-38bad758adaa (v5.7.1 β 7.5.2), 175b81d4-b217-593b-8c10-bdd268a6efba (v5.7.1 β 5.7.2), 0c95cb43-9797-5664-b871-a4a0e5867ee2 (v5.7.1 β 6.3.1) |
| CVE / Reference |
CVE-2022-25883 / GHSA-c2qf-rxjj-qqgw |
| Severity (Wiz) |
HIGH (CVSS 7.5) |
| Exploitation signals |
EPSS 2.8% Β· Public Exploit No Β· Public PoC No |
| Reachability |
NOT VERIFIED β agent must assess |
| Affected Component |
semver v5.7.1, v6.3.0, v7.3.8, /yarn.lock (lines 2607, 2612, 2617) |
| Fixed In Version |
v5.7.2 (5.x), v6.3.1 (6.x), v7.5.2 (7.x) |
| Introduced Via |
transitive β introducing package not in Wiz data; agent must trace with yarn why semver |
| File Path / Location |
/yarn.lock |
Description:
Multiple versions of the semver package across the 5.x, 6.x, and 7.x branches are vulnerable to Regular Expression Denial of Service (ReDoS) via the new Range() function when untrusted user data is provided as a range string. A maliciously crafted version range string can cause catastrophic backtracking in the regex engine, blocking the event loop and denying service. No public exploit or PoC exists. Risk is primarily DoS when untrusted version range strings reach semver.Range() β common in package management tooling or CI scripts but less likely in production service code.
AI Analysis Summary:
No reachability analysis available β the agent must assess reachability itself; weigh the exploitation signals above (EPSS 2.8%, no public exploit) and do NOT assume exploitable without tracing call sites.
Bump semver to β₯ 5.7.2 (5.x consumers), β₯ 6.3.1 (6.x consumers), β₯ 7.5.2 (7.x consumers) in /yarn.lock using yarn upgrade semver; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.
π§ Remediation Priority Order
- CVE-2022-46175 (json5) β EPSS 9.2% (highest in this set) + confirmed public exploit + public PoC; prototype pollution with potential for privilege escalation or RCE where
JSON5.parse receives untrusted input.
- CVE-2024-4068 (braces) β confirmed public exploit + public PoC; DoS via heap exhaustion when braces parser receives attacker-controlled input.
- CVE-2026-4800 (lodash) β CVSS 9.8, public exploit + PoC; RCE via
_.template imports injection β but Wiz Threat Research overrides initial access to FALSE (specific conditions required); assess _.template usage before treating as critical.
- CVE-2026-4800 (lodash-es) β same as lodash above; ESM variant; identical risk profile and Wiz override; assess call sites.
- CVE-2022-25883 (semver) β EPSS 2.8%, no public exploit or PoC; ReDoS only; likely defer if semver is only used in build/CI tooling not processing untrusted input.
β
Definition of Done
Close this issue only when ALL of the following are true:
π·οΈ Metadata
- Auto-generated by: Wiz Security Platform
- Generated at: 2026-10-08 20:56:53 UTC
- Wiz Issue ID: 5f20cf64-222b-4dd8-a6f4-0abe6700a3c0
- Wiz Issue Type: VULNERABILITY
- Affected Branch: stroeer/github-app-token/main
- Do not close manually β remediation must be validated (or an explicit disposition recorded) before closing.
View Wiz Issue
Wiz Issue ID: 5f20cf64-222b-4dd8-a6f4-0abe6700a3c0
Source Workflow: Wiz Issues β GitHub (Green Agent)
π Security Remediation Task: HIGH CVSS Exploitable CVE in Code Repository β lodash/lodash-es + CVE-2026-4800 (Γ2 packages)
π Resource Context
π€ Green Agent Analysis
No Green Agent analysis available for this issue.
π Findings (Medium+ Β· Sorted by Exploitation Likelihood)
Finding 1: CVE-2022-46175 β HIGH (json5 v1.0.1, Γ2 paths)
345d293f-706d-5946-90d1-38b375ee8c3f(v1.0.1 β fix 1.0.2),cdcff653-7701-5740-9b0e-265b16338a7f(v1.0.1 β fix 1.0.2),73842648-2925-5346-8d1f-674fbcea154c(v1.0.1 β fix 2.2.2),b3d7dfed-8e55-544f-9e9c-44c4e49bb2b1(v2.2.1 β fix 2.2.2)/yarn.lockyarn why json5/yarn.lock(lines 1926, 1933)Description:
The
JSON5.parse()method in json5 versions β€ 1.0.1 and β€ 2.2.1 does not restrict parsing of keys named__proto__, enabling prototype pollution on the returned object. An attacker who can supply a crafted JSON5 string to a code path usingJSON5.parse()can set arbitrary inherited properties on the parsed object. Depending on how the application uses that object, this may lead to denial of service, XSS, privilege escalation, or in extreme cases remote code execution. The EPSS score of 9.2% and confirmed public exploit/PoC make this a credible risk where the parse method is reachable with untrusted input.AI Analysis Summary:
No reachability analysis available β the agent must assess reachability itself; weigh the exploitation signals above (EPSS 9.2%, public exploit confirmed) and do NOT assume exploitable without tracing call sites.
Bump
json5toβ₯ 1.0.2(for 1.x consumers) andβ₯ 2.2.2(for 2.x consumers) in/yarn.lockand regenerate the lockfile withyarn upgrade json5; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.Finding 2: CVE-2024-4068 β HIGH (braces v3.0.2, Γ2 paths)
77026867-ca80-5a43-a8db-ed715bc11130,3d1578ce-23eb-581e-9d58-1458d48d616b/yarn.lock(line 592)yarn why braces/yarn.lockDescription:
The
bracesNPM package versions prior to 3.0.3 fail to limit the number of characters processed by the parser. If a malicious user supplies "imbalanced braces" as input,lib/parse.jsenters an infinite loop that continuously allocates heap memory without releasing it, eventually exhausting the JavaScript heap limit and crashing the Node.js process. This is a denial-of-service vulnerability. A public exploit exists (VulnCheck / upstream PR). Trigger requires the attacker to control input passed through abraces-consuming code path (commonly via glob/minimatch patterns).AI Analysis Summary:
No reachability analysis available β the agent must assess reachability itself; weigh the exploitation signals above (public exploit confirmed, EPSS 1.5%) and do NOT assume exploitable without tracing call sites.
Bump
bracestoβ₯ 3.0.3in/yarn.lockusingyarn upgrade braces; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.Finding 3: CVE-2026-4800 β CRITICAL (lodash v4.17.21)
c54087ec-2634-587f-9c06-ba77e0f6ec11,63781bc8-f278-50c5-9cc3-25b5044d6786/yarn.lock(line 2062)yarn why lodash/yarn.lockDescription:
The fix for CVE-2021-23337 added validation for
_.template'svariableoption but failed to apply the same validation tooptions.importskey names. Both paths feed into the sameFunction()constructor sink. When an application passes untrusted input asoptions.importskey names, an attacker can inject default-parameter expressions that execute arbitrary JavaScript at template compilation time. Additionally,_.templateusesassignInWith(enumerates inherited properties viafor..in), meaning a prior prototype pollution can cause polluted keys to flow intoFunction(). Wiz Threat Research has flagged that initial access potential is overridden to FALSE because exploitation requires specific application conditions (untrusted input reachingoptions.imports). The CVSS score of 9.8 is high, but actual risk depends heavily on code reachability.AI Analysis Summary:
Wiz Threat Research has overridden initial access potential to FALSE for CVE-2026-4800 since the vulnerability is only exploitable under specific conditions (untrusted input passed as
options.importskey names to_.template). The agent must assess whether the application passes user-controlled data to this code path before treating this as critical priority. A public PoC exists (VulnCheck).Bump
lodashtoβ₯ 4.18.0in/yarn.lockusingyarn upgrade lodash; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals and reachability assessment.Finding 4: CVE-2026-4800 β CRITICAL (lodash-es v4.17.21)
b47ac0cb-b8f5-505e-94c1-8feb5de6e33e,675f04b4-3d37-51a3-9f45-3f3d813e5ad0/yarn.lock(line 2017)yarn why lodash-es/yarn.lockDescription:
Same vulnerability class as Finding 3 (CVE-2026-4800) but affecting the ESM variant
lodash-es. The_.templatefunction'soptions.importskey names are passed unsanitized into aFunction()constructor, enabling code injection when untrusted input reaches that path. AdditionallyassignInWithenumerates inherited properties, creating a prototype-pollution amplification path. Wiz Threat Research has overridden initial access potential to FALSE. The CVSS of 9.8 is critical on paper; actual exploitability depends on whether application code routes untrusted data into_.templateimports.AI Analysis Summary:
Wiz Threat Research has overridden initial access potential to FALSE for CVE-2026-4800 on
lodash-essince the vulnerability is only exploitable under specific conditions. Same guidance as Finding 3. Agent must tracelodash-esusage withyarn why lodash-esand verify call sites before prioritising.Bump
lodash-estoβ₯ 4.18.0in/yarn.lockusingyarn upgrade lodash-es; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals and reachability assessment.Finding 5: CVE-2022-25883 β HIGH (semver, Γ5 paths)
e1893cec-af83-552b-a9fb-ec7822bf00c5(v5.7.1 β 5.7.2),eab16ed9-de63-5ba7-b535-fd20903c850b(v7.3.8 β 7.5.2),d1e841ed-5f79-53f7-94fb-3a0bfb00ed75(v6.3.0 β 6.3.1),e4ecd1cd-4712-50d7-b7f3-38bad758adaa(v5.7.1 β 7.5.2),175b81d4-b217-593b-8c10-bdd268a6efba(v5.7.1 β 5.7.2),0c95cb43-9797-5664-b871-a4a0e5867ee2(v5.7.1 β 6.3.1)/yarn.lock(lines 2607, 2612, 2617)yarn why semver/yarn.lockDescription:
Multiple versions of the
semverpackage across the 5.x, 6.x, and 7.x branches are vulnerable to Regular Expression Denial of Service (ReDoS) via thenew Range()function when untrusted user data is provided as a range string. A maliciously crafted version range string can cause catastrophic backtracking in the regex engine, blocking the event loop and denying service. No public exploit or PoC exists. Risk is primarily DoS when untrusted version range strings reachsemver.Range()β common in package management tooling or CI scripts but less likely in production service code.AI Analysis Summary:
No reachability analysis available β the agent must assess reachability itself; weigh the exploitation signals above (EPSS 2.8%, no public exploit) and do NOT assume exploitable without tracing call sites.
Bump
semvertoβ₯ 5.7.2(5.x consumers),β₯ 6.3.1(6.x consumers),β₯ 7.5.2(7.x consumers) in/yarn.lockusingyarn upgrade semver; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.π§ Remediation Priority Order
JSON5.parsereceives untrusted input._.templateimports injection β but Wiz Threat Research overrides initial access to FALSE (specific conditions required); assess_.templateusage before treating as critical.β Definition of Done
Close this issue only when ALL of the following are true:
yarn list <package>confirms the upgraded version is in use and no older vulnerable version remainsyarn auditafter upgrade)π·οΈ Metadata
View Wiz Issue
Wiz Issue ID: 5f20cf64-222b-4dd8-a6f4-0abe6700a3c0
Source Workflow: Wiz Issues β GitHub (Green Agent)