Intel

AIKIDO-2024-10521

@gouvfr/dsfr is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Dec 9, 2024

100

Critical Risk

This Affects:

JS@gouvfr/dsfr
0.1.0 - 1.12.1
Fixed in 1.13.0
Are you affected? Scan for Free

TL;DR

Affected versions of @gouvfr/dsfr use polyfill[.]io, which is taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@gouvfr/dsfr is vulnerable to Malicious Code in versions 0.1.0 - 1.12.1.

How to fix this

Upgrade the @gouvfr/dsfr library to the patch version.