VDB
Sign up
CRITICAL9.8

GHSA-hc6q-2mpp-qw7j

Cross-realm object access in Webpack 5

Quick fix

GHSA-hc6q-2mpp-qw7j — webpack: upgrade to the fixed version with the command below.

npm install webpack@5.76.0

Details

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/webpack
Introduced in: 5.0.0Fixed in: 5.76.0
Fixnpm install webpack@5.76.0

References