Intel

AIKIDO-2024-10144

html-webpack-polyfill-runtime-plugin is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Jun 27, 2024

100

Critical Risk

Are you affected? Scan for Free

TL;DR

html-webpack-polyfill-runtime-plugin uses polyfill[.]io, which is taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you use html-webpack-polyfill-runtime-plugin.

Background info

html-webpack-polyfill-runtime-plugin is vulnerable to Malicious Code in all versions.

How to fix this

Remove this package from your application.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform