Skip to content

CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports#224

Open
keithchong wants to merge 1 commit intoredhat-developer:mainfrom
keithchong:main-UpdateLodashVersion
Open

CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports#224
keithchong wants to merge 1 commit intoredhat-developer:mainfrom
keithchong:main-UpdateLodashVersion

Conversation

@keithchong
Copy link
Copy Markdown
Collaborator

@aali309 , updating version for now. I will be bumping up the dynamic plugin SDK, and removing the dependency on the old dagre package (which pulls in lodash) and will use @dagrejs/dagre instead.

template imports

Signed-off-by: Keith Chong <kykchong@redhat.com>
@openshift-ci openshift-ci Bot requested a review from wtam2018 April 28, 2026 17:44
@keithchong keithchong requested review from aali309 and removed request for wtam2018 April 28, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant