Intel

AIKIDO-2024-10141

albertcht/invisible-recaptcha is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526

100

Critical Risk

This Affects:

TL;DR

albertcht/invisible-recaptcha uses polyfill[.]io, which is taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you use albertcht/invisible-recaptcha.

Background info

albertcht/invisible-recaptcha is vulnerable to Malicious Code in all versions.

How to fix this

Remove this package from your application.