Intel

AIKIDO-2024-10143

@isoden/polyfill-io-html-webpack-plugin is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Jun 27, 2024

100

Critical Risk

Are you affected? Scan for Free

TL;DR

@isoden/polyfill-io-html-webpack-plugin uses polyfill[.]io, which is taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you use @isoden/polyfill-io-html-webpack-plugin.

Background info

@isoden/polyfill-io-html-webpack-plugin is vulnerable to Malicious Code in all versions.

How to fix this

Remove this package from your application.