S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Apr 7, 2026

CVE-2021-23337 Scanner

CVE-2021-23337 Scanner - Remote Code Execution (RCE) vulnerability in Lodash

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-23337
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Lodashby n/a
prior to 4.17.21
Updated Aug 21, 2026View on NVD →
Detail

The Lodash library, a widely used JavaScript utility library, is employed in various web applications for performing common programming tasks. It is favored by developers for its ease of use and comprehensive method coverage, which simplifies JavaScript development. Lodash is found in many front-end and back-end projects, including those built with Node.js. Developers opt for Lodash due to its performance optimizations and modular structure, which allows for selective function imports. It is incorporated in applications ranging from simple websites to complex enterprise solutions globally. With a vast user base, vulnerabilities in Lodash can have significant impacts on numerous applications reliant on its functionalities.

A server-side template injection (SSTI) vulnerability has been discovered in Lodash, which can be exploited for remote code execution (RCE). This vulnerability exists prior to version 4.17.21 and is triggered via the template function. The flaw allows attackers to craft payloads that can execute arbitrary commands on the host. Such a vulnerability is critical, as it bypasses normal restrictions and allows direct interaction with the server's environment. Exploits leveraging this flaw can lead to unauthorized access and control over the affected system, posing a serious security threat.

This vulnerability in Lodash involves specific functions that interpret user inputs without proper validation, enabling the execution of arbitrary commands. The vulnerable endpoint is typically associated with the template function, where user inputs might be processed. Attackers exploit this by sending crafted requests, such as HTTP POST or GET requests, to execute malicious code. These requests manipulate available parameters in the template function and leverage the execution context to perform unauthorized actions. Therefore, the attack's success depends on exploiting the improper handling of input data within Lodash's template engine.

Exploiting the Lodash vulnerability allows attackers to carry out arbitrary command executions, impacting the security and integrity of the affected systems. Such attacks can result in unauthorized data manipulation, deletion, or theft. Additionally, attackers can gain persistent control over the compromised system, potentially extending their attack to other connected systems. Should sensitive information be compromised, this can lead to data breaches, financial losses, and damaging reputational consequences for the affected organization.

REFERENCES

Solution Advice
  • Update Lodash to version 4.17.21 or later.
  • Implement strict input validation to prevent illegal data execution.
  • Conduct regular security audits of third-party libraries to identify potential risks.
  • Enable threat detection and monitoring systems to identify unusual activities.
  • Review and restrict permissions to minimize the impact of potential exploits.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.