Skip to content

lodash vulnerability - need upgrade to 4.17.23 #8216

@markdevocht

Description

@markdevocht

What happened?

Upgrading lodash to 4.17.23, vulnerability fix:

CVE-2025-13465 (GHSA-xxjr-mmjv-4gpg)
Published: January 21, 2026 (5 days ago)
Severity: Moderate
Issue: Prototype Pollution in _.unset and _.omit functions
Affected: lodash 4.0.0 through 4.17.22
Fixed in: 4.17.23

What was the expected behaviour?

No response

Was it tested on latest react-native-navigation?

  • I have tested this issue on the latest react-native-navigation release and it still reproduces.

Help us reproduce this issue!

No response

In what environment did this happen?

React Native Navigation version:
React Native version:
Has Fabric (React Native's new rendering system) enabled: (yes/no)
Node version:

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions