Forum Discussion

InfinaAdmin's avatar
InfinaAdmin
Community Member
4 hours ago

Critical security finding Lodash versions < v4.18 when will a Storyline 360 patch be released?

Hello,

We have received a Critical security vulnerability for our Storyline 360 packages. A quick online search shows a Lodash vulnerability CVE-2026-4800 (Arbitrary Code Injection) in the _.template() function. 

https://nvd.nist.gov/vuln/detail/CVE-2026-4800

Critical security findings have serious implications that affect our ability to release updates.

I have created a Scorm1.2 output package today (I am using the current Storyline 360 build - July 8 v3.121.37380.0) and Lodash v 4.17.21 is still included in html5/lib/scripts/bootstrapper.min.js. We have attempted to mitigate by manually updating Lodash, but that does not work because Storyline 360 uses a custom version of Lodash. It seems that we have no choice but to wait until a release is made that contains a patch.

I have searched online, and I only see Lodash vulnerabilities from several years ago. Is there any information as to a Storyline 360 update that will contain the recommended patched version of Lodash 4.18.1?

No RepliesBe the first to reply