Intel

AIKIDO-2024-10140

gatsby-plugin-polyfill-io is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Jun 26, 2024

100

Critical Risk

This Affects:

Are you affected? Scan for Free

TL;DR

gatsby-plugin-polyfill-io uses polyfill[.]io, which is taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you use gatsby-plugin-polyfill-io.

Background info

gatsby-plugin-polyfill-io is vulnerable to Malicious Code in versions 1.0.2 - 1.1.0.

How to fix this

Remove this package from your application.