Skip to content

HIGH CVSS Exploitable CVE in Code RepositoryΒ #15

Description

@wiz-issues-97583b7245

πŸ” Security Remediation Task: HIGH CVSS Exploitable CVE in Code Repository β€” lodash/lodash-es + CVE-2026-4800 (Γ—2 packages)

For AI Agent: This issue is auto-generated from Wiz. All information needed to remediate is below. Do not ask for clarification. Weigh the exploitation signals (EPSS / public exploit / PoC) and actual code reachability before acting β€” not every listed finding must become a code change: deferring a genuinely unreachable, low-signal, non-critical finding (with a recorded reason) is a valid disposition. Never claim to fix a CVE the resource is not actually exposed to.


πŸ“ Resource Context

Field Value
Resource Name stroeer/github-app-token
Resource Type GitHub Repository (github#repository)
External ID / ARN github.com##stroeer/github-app-token
Region N/A
Cloud GitHub
Wiz Issue Link https://app.wiz.io/issues#~%28issue~'5f20cf64-222b-4dd8-a6f4-0abe6700a3c0%29

πŸ€– Green Agent Analysis

No Green Agent analysis available for this issue.


πŸ“‹ Findings (Medium+ Β· Sorted by Exploitation Likelihood)


Finding 1: CVE-2022-46175 β€” HIGH (json5 v1.0.1, Γ—2 paths)
Field Value
Finding IDs 345d293f-706d-5946-90d1-38b375ee8c3f (v1.0.1 β†’ fix 1.0.2), cdcff653-7701-5740-9b0e-265b16338a7f (v1.0.1 β†’ fix 1.0.2), 73842648-2925-5346-8d1f-674fbcea154c (v1.0.1 β†’ fix 2.2.2), b3d7dfed-8e55-544f-9e9c-44c4e49bb2b1 (v2.2.1 β†’ fix 2.2.2)
CVE / Reference CVE-2022-46175 / GHSA-9c47-m6qq-7p4h
Severity (Wiz) HIGH (CVSS 8.8)
Exploitation signals EPSS 9.2% Β· Public Exploit Yes Β· Public PoC Yes
Reachability NOT VERIFIED β€” agent must assess
Affected Component json5 v1.0.1 and v2.2.1, /yarn.lock
Fixed In Version v1.0.2 (for 1.x branch), v2.2.2 (for 2.x branch)
Introduced Via transitive β€” introducing package not in Wiz data; agent must trace with yarn why json5
File Path / Location /yarn.lock (lines 1926, 1933)

Description:
The JSON5.parse() method in json5 versions ≀ 1.0.1 and ≀ 2.2.1 does not restrict parsing of keys named __proto__, enabling prototype pollution on the returned object. An attacker who can supply a crafted JSON5 string to a code path using JSON5.parse() can set arbitrary inherited properties on the parsed object. Depending on how the application uses that object, this may lead to denial of service, XSS, privilege escalation, or in extreme cases remote code execution. The EPSS score of 9.2% and confirmed public exploit/PoC make this a credible risk where the parse method is reachable with untrusted input.

AI Analysis Summary:
No reachability analysis available β€” the agent must assess reachability itself; weigh the exploitation signals above (EPSS 9.2%, public exploit confirmed) and do NOT assume exploitable without tracing call sites.

Bump json5 to β‰₯ 1.0.2 (for 1.x consumers) and β‰₯ 2.2.2 (for 2.x consumers) in /yarn.lock and regenerate the lockfile with yarn upgrade json5; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.


Finding 2: CVE-2024-4068 β€” HIGH (braces v3.0.2, Γ—2 paths)
Field Value
Finding IDs 77026867-ca80-5a43-a8db-ed715bc11130, 3d1578ce-23eb-581e-9d58-1458d48d616b
CVE / Reference CVE-2024-4068 / GHSA-grv7-fg5c-xmjg
Severity (Wiz) HIGH (CVSS 7.5)
Exploitation signals EPSS 1.5% Β· Public Exploit Yes Β· Public PoC Yes
Reachability NOT VERIFIED β€” agent must assess
Affected Component braces v3.0.2, /yarn.lock (line 592)
Fixed In Version v3.0.3
Introduced Via transitive β€” introducing package not in Wiz data; agent must trace with yarn why braces
File Path / Location /yarn.lock

Description:
The braces NPM package versions prior to 3.0.3 fail to limit the number of characters processed by the parser. If a malicious user supplies "imbalanced braces" as input, lib/parse.js enters an infinite loop that continuously allocates heap memory without releasing it, eventually exhausting the JavaScript heap limit and crashing the Node.js process. This is a denial-of-service vulnerability. A public exploit exists (VulnCheck / upstream PR). Trigger requires the attacker to control input passed through a braces-consuming code path (commonly via glob/minimatch patterns).

AI Analysis Summary:
No reachability analysis available β€” the agent must assess reachability itself; weigh the exploitation signals above (public exploit confirmed, EPSS 1.5%) and do NOT assume exploitable without tracing call sites.

Bump braces to β‰₯ 3.0.3 in /yarn.lock using yarn upgrade braces; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.


Finding 3: CVE-2026-4800 β€” CRITICAL (lodash v4.17.21)
Field Value
Finding IDs c54087ec-2634-587f-9c06-ba77e0f6ec11, 63781bc8-f278-50c5-9cc3-25b5044d6786
CVE / Reference CVE-2026-4800 / GHSA-r5fr-rjxr-66jc
Severity (Wiz) CRITICAL (CVSS 9.8)
Exploitation signals EPSS 2.6% Β· Public Exploit Yes Β· Public PoC Yes
Reachability NOT VERIFIED β€” agent must assess (Wiz Threat Research note: initial access potential overridden to FALSE; only exploitable under specific conditions)
Affected Component lodash v4.17.21, /yarn.lock (line 2062)
Fixed In Version v4.18.0
Introduced Via transitive β€” introducing package not in Wiz data; agent must trace with yarn why lodash
File Path / Location /yarn.lock

Description:
The fix for CVE-2021-23337 added validation for _.template's variable option but failed to apply the same validation to options.imports key names. Both paths feed into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary JavaScript at template compilation time. Additionally, _.template uses assignInWith (enumerates inherited properties via for..in), meaning a prior prototype pollution can cause polluted keys to flow into Function(). Wiz Threat Research has flagged that initial access potential is overridden to FALSE because exploitation requires specific application conditions (untrusted input reaching options.imports). The CVSS score of 9.8 is high, but actual risk depends heavily on code reachability.

AI Analysis Summary:
Wiz Threat Research has overridden initial access potential to FALSE for CVE-2026-4800 since the vulnerability is only exploitable under specific conditions (untrusted input passed as options.imports key names to _.template). The agent must assess whether the application passes user-controlled data to this code path before treating this as critical priority. A public PoC exists (VulnCheck).

Bump lodash to β‰₯ 4.18.0 in /yarn.lock using yarn upgrade lodash; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals and reachability assessment.


Finding 4: CVE-2026-4800 β€” CRITICAL (lodash-es v4.17.21)
Field Value
Finding IDs b47ac0cb-b8f5-505e-94c1-8feb5de6e33e, 675f04b4-3d37-51a3-9f45-3f3d813e5ad0
CVE / Reference CVE-2026-4800 / GHSA-r5fr-rjxr-66jc
Severity (Wiz) CRITICAL (CVSS 9.8)
Exploitation signals EPSS 2.6% Β· Public Exploit Yes Β· Public PoC Yes
Reachability NOT VERIFIED β€” agent must assess (Wiz Threat Research note: initial access potential overridden to FALSE; only exploitable under specific conditions)
Affected Component lodash-es v4.17.21, /yarn.lock (line 2017)
Fixed In Version v4.18.0
Introduced Via transitive β€” introducing package not in Wiz data; agent must trace with yarn why lodash-es
File Path / Location /yarn.lock

Description:
Same vulnerability class as Finding 3 (CVE-2026-4800) but affecting the ESM variant lodash-es. The _.template function's options.imports key names are passed unsanitized into a Function() constructor, enabling code injection when untrusted input reaches that path. Additionally assignInWith enumerates inherited properties, creating a prototype-pollution amplification path. Wiz Threat Research has overridden initial access potential to FALSE. The CVSS of 9.8 is critical on paper; actual exploitability depends on whether application code routes untrusted data into _.template imports.

AI Analysis Summary:
Wiz Threat Research has overridden initial access potential to FALSE for CVE-2026-4800 on lodash-es since the vulnerability is only exploitable under specific conditions. Same guidance as Finding 3. Agent must trace lodash-es usage with yarn why lodash-es and verify call sites before prioritising.

Bump lodash-es to β‰₯ 4.18.0 in /yarn.lock using yarn upgrade lodash-es; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals and reachability assessment.


Finding 5: CVE-2022-25883 β€” HIGH (semver, Γ—5 paths)
Field Value
Finding IDs e1893cec-af83-552b-a9fb-ec7822bf00c5 (v5.7.1 β†’ 5.7.2), eab16ed9-de63-5ba7-b535-fd20903c850b (v7.3.8 β†’ 7.5.2), d1e841ed-5f79-53f7-94fb-3a0bfb00ed75 (v6.3.0 β†’ 6.3.1), e4ecd1cd-4712-50d7-b7f3-38bad758adaa (v5.7.1 β†’ 7.5.2), 175b81d4-b217-593b-8c10-bdd268a6efba (v5.7.1 β†’ 5.7.2), 0c95cb43-9797-5664-b871-a4a0e5867ee2 (v5.7.1 β†’ 6.3.1)
CVE / Reference CVE-2022-25883 / GHSA-c2qf-rxjj-qqgw
Severity (Wiz) HIGH (CVSS 7.5)
Exploitation signals EPSS 2.8% Β· Public Exploit No Β· Public PoC No
Reachability NOT VERIFIED β€” agent must assess
Affected Component semver v5.7.1, v6.3.0, v7.3.8, /yarn.lock (lines 2607, 2612, 2617)
Fixed In Version v5.7.2 (5.x), v6.3.1 (6.x), v7.5.2 (7.x)
Introduced Via transitive β€” introducing package not in Wiz data; agent must trace with yarn why semver
File Path / Location /yarn.lock

Description:
Multiple versions of the semver package across the 5.x, 6.x, and 7.x branches are vulnerable to Regular Expression Denial of Service (ReDoS) via the new Range() function when untrusted user data is provided as a range string. A maliciously crafted version range string can cause catastrophic backtracking in the regex engine, blocking the event loop and denying service. No public exploit or PoC exists. Risk is primarily DoS when untrusted version range strings reach semver.Range() β€” common in package management tooling or CI scripts but less likely in production service code.

AI Analysis Summary:
No reachability analysis available β€” the agent must assess reachability itself; weigh the exploitation signals above (EPSS 2.8%, no public exploit) and do NOT assume exploitable without tracing call sites.

Bump semver to β‰₯ 5.7.2 (5.x consumers), β‰₯ 6.3.1 (6.x consumers), β‰₯ 7.5.2 (7.x consumers) in /yarn.lock using yarn upgrade semver; if transitive with no clean root bump, weigh override vs. defer per the exploitation signals.


🧭 Remediation Priority Order

  1. CVE-2022-46175 (json5) β€” EPSS 9.2% (highest in this set) + confirmed public exploit + public PoC; prototype pollution with potential for privilege escalation or RCE where JSON5.parse receives untrusted input.
  2. CVE-2024-4068 (braces) β€” confirmed public exploit + public PoC; DoS via heap exhaustion when braces parser receives attacker-controlled input.
  3. CVE-2026-4800 (lodash) β€” CVSS 9.8, public exploit + PoC; RCE via _.template imports injection β€” but Wiz Threat Research overrides initial access to FALSE (specific conditions required); assess _.template usage before treating as critical.
  4. CVE-2026-4800 (lodash-es) β€” same as lodash above; ESM variant; identical risk profile and Wiz override; assess call sites.
  5. CVE-2022-25883 (semver) β€” EPSS 2.8%, no public exploit or PoC; ReDoS only; likely defer if semver is only used in build/CI tooling not processing untrusted input.

βœ… Definition of Done

Close this issue only when ALL of the following are true:

  • Each finding above has been either remediated OR given an explicit, recorded disposition (fixed / deferred-with-reason / false-positive) β€” deferring a low-signal, unreachable, non-critical finding is a valid disposition
  • For each remediated finding, yarn list <package> confirms the upgraded version is in use and no older vulnerable version remains
  • No new medium+ severity findings introduced by the fix (run yarn audit after upgrade)
  • The change is traceable (PR link, change ID, or deployment reference)

🏷️ Metadata

  • Auto-generated by: Wiz Security Platform
  • Generated at: 2026-10-08 20:56:53 UTC
  • Wiz Issue ID: 5f20cf64-222b-4dd8-a6f4-0abe6700a3c0
  • Wiz Issue Type: VULNERABILITY
  • Affected Branch: stroeer/github-app-token/main
  • Do not close manually β€” remediation must be validated (or an explicit disposition recorded) before closing.

View Wiz Issue
Wiz Issue ID: 5f20cf64-222b-4dd8-a6f4-0abe6700a3c0
Source Workflow: Wiz Issues β†’ GitHub (Green Agent)

Activity

  1. claudesecuritypatcher commented on Oct 9, 2026

    @claudesecuritypatcher

    Fixed in #16: an in-range yarn.lock refresh puts lodash/lodash-es on 4.18.1, json5 on 1.0.2/2.2.3, braces on 3.0.3 and semver on 5.7.2/6.3.1/7.8.5. All of these are only in the xo lint toolchain and none is bundled into dist. CI: Wiz Vulnerability Scanner passes. Test fails only at the Prettier step on README.md, which already fails on main. Recorded on the Wiz posture issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions