Forum Discussion
Critical security finding Lodash versions < v4.18 when will a Storyline 360 patch be released?
Hello,
We have received a Critical security vulnerability for our Storyline 360 packages. A quick online search shows a Lodash vulnerability CVE-2026-4800 (Arbitrary Code Injection) in the _.template() function.
https://nvd.nist.gov/vuln/detail/CVE-2026-4800
Critical security findings have serious implications that affect our ability to release updates.
I have created a Scorm1.2 output package today (I am using the current Storyline 360 build - July 8 v3.121.37380.0) and Lodash v 4.17.21 is still included in html5/lib/scripts/bootstrapper.min.js. We have attempted to mitigate by manually updating Lodash, but that does not work because Storyline 360 uses a custom version of Lodash. It seems that we have no choice but to wait until a release is made that contains a patch.
I have searched online, and I only see Lodash vulnerabilities from several years ago. Is there any information as to a Storyline 360 update that will contain the recommended patched version of Lodash 4.18.1?
Related Content
- 1 year ago