Intel

AIKIDO-2024-10154

pdoc is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Jun 28, 2024

100

Critical Risk

This Affects:

pythonpdoc
0.0.1 - 14.5.0
Fixed in 14.5.1
Are you affected? Scan for Free

TL;DR

In some parts of the documentation, pdoc uses polyfill[.]io, which is known for serving malicious code.

Who does this affect?

You are affected if you use pdoc.

Background info

pdoc is vulnerable to Malicious Code in versions 0.0.1 - 14.5.0.

How to fix this

Upgrade to a patch version (version 14.5.1).