Skip to content

fix(deps): bump lodash and lodash-es to 4.18.1 (CVE-2021-23337) - #235

Open
focuslight-nr wants to merge 2 commits into
reconurge:mainfrom
focuslight-nr:fix/lodash-cve-2021-23337
Open

focuslight-nr wants to merge 2 commits into
reconurge:mainfrom
focuslight-nr:fix/lodash-cve-2021-23337

Conversation

@focuslight-nr

Copy link
Copy Markdown

What

Bumps lodash and lodash-es from 4.17.21 to 4.18.1 in both lockfiles. Lockfile-only: every range that reaches them already allows 4.18.x (recharts ^4.17.21, force-graph/kapsule lodash-es@4, the conventional-changelog tooling ^4.17.15), so no package.json changes.

Why

4.17.21 is affected by CVE-2021-23337 (command injection via _.template, EPSS ≈ 21%), plus CVE-2025-13465, CVE-2026-2950 and CVE-2026-4800. recharts pulls lodash into the app's production bundle, and lodash-es comes in through the graph view (force-graph/kapsule).

Two lockfiles, two commits

  • a8cf218 root yarn.lock – what CI and local dev use (yarn install --frozen-lockfile).
  • b700942 flowsint-app/yarn.lock – flowsint-app/Dockerfile is built with context ./flowsint-app in docker-compose.yml, so the image installs from this file, not the root one. The root bump alone would not reach the image.

Only those two lock entries were re-resolved, and the same entries were used in both files. yarn upgrade was avoided because in a workspace it silently skips transitive packages and pulls in unrelated bumps.

Verification

  • yarn install --frozen-lockfile passes at the root.
  • flowsint-app: npx vitest run (15 passed) and yarn build succeed.
  • A plain yarn install in a standalone copy of flowsint-app/ (what the Dockerfile runs) installs lodash 4.18.1 and lodash-es 4.18.1. The same steps on main install 4.17.21.

Run locally on Node 26; CI uses 22.

Not in this PR

  • commitizen still pins lodash 4.17.21 exactly. It is dev-only commit tooling, so nothing ships with it. commitizen 4.3.2 (within the declared ^4.3.1) moves the pin to 4.18.1 but also brings in @commitlint 21 and ~30 other changes, so it seemed better as its own PR.
  • flowsint-app/yarn.lock is out of sync with flowsint-app/package.json. It was last updated in Oct 2025, and yarn install --frozen-lockfile fails against it. Because the Dockerfile runs yarn install without --frozen-lockfile, every image build quietly re-resolves the difference (about 3.5k lockfile lines), so the image isn't pinned to anything reviewed. Scanners that read that lockfile directly will also keep flagging the orphaned lodash@4.17.21 entry that belongs to stale commitizen entries, even though a real install prunes it. Possible fixes are regenerating it, or building the image from the repo root against the root lockfile. That is a design decision, so I've left it to you.

🤖 Generated with Claude Code

focuslight-nr and others added 2 commits September 25, 2026 17:21
lodash and lodash-es 4.17.21 are affected by CVE-2021-23337 (command
injection in `template`, EPSS ~21%), CVE-2025-13465, CVE-2026-2950 and
CVE-2026-4800. Every range that reaches them already allows 4.18.x
(recharts ^4.17.21, force-graph/kapsule lodash-es 4, the conventional-
changelog tooling ^4.17.15), so this is a lockfile-only change with no
package.json edits.

Only those two entries were re-resolved; `yarn upgrade` was not used
because it ignores transitive packages in a workspace and drags in
unrelated bumps. The one remaining lodash 4.17.21 is commitizen's exact
pin (dev-only commit tooling); commitizen 4.3.2 moves that pin to 4.18.1
but also pulls in @commitlint 21, so it is left for a separate change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…kfile

flowsint-app/Dockerfile (used by docker-compose with context
./flowsint-app) installs from flowsint-app/yarn.lock, not the root
lockfile, so the root bump alone does not reach the built image.

Same two entries, spliced in unchanged from the root lockfile. A plain
`yarn install` in a standalone copy of flowsint-app - what the Dockerfile
runs - now resolves lodash and lodash-es to 4.18.1 (4.17.21 before).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant