Packs ECMAScript/CommonJs/AMD modules for the browser. Allows you to split your codebase into multiple bundles, which can be loaded on demand. Supports loaders to preprocess files, i.e. json, jsx, es7, css, less, ... and your custom stuff.
86%
Total Score
100
100
100
88
100
All 12 workflows were analyzed successfully, all 76 action references are pinned, and no untrusted checkout or script injection was found. However, high-confidence github-app findings in dependabot and release workflows plus high-confidence secrets-inherit indicate broader-than-needed credentials; top-level write permissions add mild exposure, while the low-confidence cache finding is only hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-318059 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. webpack is vulnerable to Prototype Pollution in versions 5.0.0 - 5.107.1. | 5.0.0 - 5.107.1 | Low |
CVE-2025-68458 webpack is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.49.0 - 5.104.0. | 5.49.0 - 5.104.0 | Low |
AIKIDO-2025-10967 webpack is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.49.0 - 5.103.0. | 5.49.0 - 5.103.0 | Medium |
AIKIDO-2025-10746 webpack is vulnerable to Improper Access Control in versions 5.0.0 - 5.75.0. | 5.0.0 - 5.75.0 | Medium |
AIKIDO-2024-10289 webpack is vulnerable to Cross-site Scripting (XSS) in versions 5.0.0 - 5.93.0. | 5.0.0 - 5.93.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
events Version ^3.2.0 | — | — |
mime-db Version ^1.54.0 | — | — |
tapable Version ^2.3.0 | — | — |
watchpack Version ^2.5.2 | — | — |
graceful-fs Version ^4.2.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.