Multiple prototype pollution vulnerabilities in Lodash (CVE-2019-10744, CVSS 9.1), the most widely-used JavaScript utility library with ~50M weekly downloads. The vulnerabilities affected virtually every major Node.js application and took years to be fully patched across the ecosystem.
VULN_RECENT_FREQUENCY + maintainer health preconditions
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | VULN_RECENT_FREQUENCY + maintainer health preconditions |
| Socket | After damage | Detects after CVE published |
| Snyk | After damage | CVE detection after publication; reactive not proactive |
| Sonatype (Nexus) | After damage | Detects after CVE published |
| Black Duck | After damage | Detects after CVE published |
| Endor Labs | After damage | CVE detection + reachability analysis after publication; reactive |