FlawAtlas
Search the atlas
CVE-2021-23358 High

CVE-2021-23358

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Exploit probability 4.1%
Published March 29, 2021
Required by Not available
Last source change July 8, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

22 explicit affected versions

npm underscore

03 / CONNECTIONS

Connected vulnerabilities

related SNYK-JAVA-ORGWEBJARSBOWER-1081504
related SNYK-JAVA-ORGWEBJARSBOWERGITHUBJASHKENAS-1081505
related SNYK-JAVA-ORGWEBJARSNPM-1081503
related SNYK-JS-UNDERSCORE-1080984

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2021-23358

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

View original source
Open Source Vulnerabilities GHSA-cf4h-3jhx-xvhq

The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

View original source

05 / REFERENCES

Further evidence