Intel

AIKIDO-2024-10146

psgganesh/anchor is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Jun 27, 2024

100

Critical Risk

This Affects:

Are you affected? Scan for Free

TL;DR

psgganesh/anchor uses polyfill[.]io, which is taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you use psgganesh/anchor.

Background info

psgganesh/anchor is vulnerable to Malicious Code in all versions.

How to fix this

Remove this package from your application.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform