Intel

AIKIDO-2024-10552

@rspack/core is vulnerable to Malicious Code

Malicious Code Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

100

Critical Risk

This Affects:

JS@rspack/core
1.1.7 - 1.1.7
Fixed in 1.1.8

TL;DR

Affected version of this package is published using a compromised npm token and contains multiple security vulnerabilities. Users are strongly advised to avoid this version and update or downgrade to a secure release immediately.

Who does this affect?

You are affected if you are using version 1.1.7.

Background info

@rspack/core is vulnerable to Malicious Code in versions 1.1.7 - 1.1.7.

How to fix this

Upgrade the @rspack/core library to the patch version.