Intel

AIKIDO-2024-10147

mobius1-selectr is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Jun 27, 2024

50

Medium Risk

This Affects:

Are you affected? Scan for Free

TL;DR

Use of mobius1-selectr is commonly linked to the use of cdn.polyfill[.]io, which was taken over by attackers and serves harmful code. polyfill itself is not included in this library, but integration is possible.

Who does this affect?

You are affected if you use mobius1-selectr and you have included cdn.polyfill[.]io script resources on any of your web pages.

Background info

mobius1-selectr is vulnerable to Malicious Code in all versions.

How to fix this

Remove the use of cdn.polyfill[.]io across your application.