High Severity Vulnerability
This vulnerability has been rated as High severity. Immediate action is recommended.
CVE-2024-38526
HighVulnerability Description
pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
CPUJAN2025
Oracle Critical Patch Update Advisory - January 2025
References & Resources
-
https://github.com/mitmproxy/pdoc/pull/703security-advisories@github.com
-
https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62security-advisories@github.com
-
https://sansec.io/research/polyfill-supply-chain-attacksecurity-advisories@github.com
-
https://www.vicarius.io/vsociety/posts/polyfillio-in-pdoc-cve-2024-38526security-advisories@github.com
-
https://github.com/mitmproxy/pdoc/pull/703af854a3a-2127-422b-91ae-364da2661108
-
https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62af854a3a-2127-422b-91ae-364da2661108
-
https://sansec.io/research/polyfill-supply-chain-attackaf854a3a-2127-422b-91ae-364da2661108
-
https://www.vicarius.io/vsociety/posts/polyfillio-in-pdoc-cve-2024-38526af854a3a-2127-422b-91ae-364da2661108
Severity Details
Key Information
- Published Date
- June 26, 2024
