webpack is vulnerable to Improper Access Control
60
Medium Risk
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
You are affected if you are using a version that falls within the vulnerable range.
webpack is vulnerable to Improper Access Control in versions 5.0.0 - 5.75.0.
Upgrade the webpack library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant