Intel

AIKIDO-2025-10746

webpack is vulnerable to Improper Access Control

Improper Access ControlCVE-2023-28154 Published Oct 24, 2025

60

Medium Risk

This Affects:

JSwebpack
5.0.0 - 5.75.0
Fixed in 5.76.0
Are you affected? Scan for Free

TL;DR

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

webpack is vulnerable to Improper Access Control in versions 5.0.0 - 5.75.0.

How to fix this

Upgrade the webpack library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform