CRITICAL 9.8 npm

Cross-realm object access in Webpack 5

GHSA-hc6q-2mpp-qw7j · CVE-2023-28154

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Ready to move

Start Securing

Free, no credit card | First findings in minutes