The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.4.4-2ubuntu1+esm1", "binary_name": "libjs-underscore" }, { "binary_version": "1.4.4-2ubuntu1+esm1", "binary_name": "node-underscore" } ] }