Skip to content

Snyk vulnerability: Prototype Pollution (CVE-2025-13465) via lodash dependency #4398

Description

@ksadhwani

Description

The package @twilio-paste/color-contrast-utils (^5.0.0) introduces a transitive dependency on lodash that is flagged by Snyk.

Vulnerability:

  • CVE: CVE-2025-13465
  • Snyk ID: SNYK-JS-LODASH-15053838
  • CWE: CWE-1321 (Prototype Pollution)

Fixed version:

  • lodash >= 4.17.23

Please update the transitive lodash dependency used by @twilio-paste/color-contrast-utils to a non-vulnerable version.

Environment:

  • Package: @twilio-paste/color-contrast-utils@5.0.0
  • Vulnerability scanner: Snyk

Link to Reproduction

https://www.npmjs.com/package/@twilio-paste/color-contrast-utils

Paste Core Version

5.0.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    Area: InfrastructureRelated to our infrastructure and build toolsType: BugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions