Intel

AIKIDO-2024-10140

gatsby-plugin-polyfill-io is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Jun 26, 2024

100

Critical Risk

This Affects:

Are you affected? Scan for Free

TL;DR

gatsby-plugin-polyfill-io uses polyfill[.]io, which is taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you use gatsby-plugin-polyfill-io.

Background info

gatsby-plugin-polyfill-io is vulnerable to Malicious Code in versions 1.0.2 - 1.1.0.

How to fix this

Remove this package from your application.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform