Critical Vulnerabilities 2018-2020 Incident #58 CVE-2019-10744

Lodash prototype pollution

Estimated Financial Impact
Virtually every Node.js app
Blast Radius
CVE-2019-10744 CVSS 9.1; 50M weekly downloads

What Happened

Multiple prototype pollution vulnerabilities in Lodash (CVE-2019-10744, CVSS 9.1), the most widely-used JavaScript utility library with ~50M weekly downloads. The vulnerabilities affected virtually every major Node.js application and took years to be fully patched across the ecosystem.

✓

Risk Guard: Caught

VULN_RECENT_FREQUENCY + maintainer health preconditions

Risk Guard Check Codes That Flag This Incident

VULN_RECENT_FREQUENCY

How Every Tool Performed

1 Caught 0 Partial 5 After damage 0 Missed
Tool Verdict Details
OSS Risk Guard Caught VULN_RECENT_FREQUENCY + maintainer health preconditions
Socket After damage Detects after CVE published
Snyk After damage CVE detection after publication; reactive not proactive
Sonatype (Nexus) After damage Detects after CVE published
Black Duck After damage Detects after CVE published
Endor Labs After damage CVE detection + reachability analysis after publication; reactive
← Text4Shell (CVE-2022-42889) PAC-Resolver SSRF/RCE →