CVE-2024-38526High· 7.2▾ MidnightPoC availablepdoc embeds link to malicious CDN if math mode is enabled
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 39.6 · likelihood 0.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.8%
2 GitHub repos
Documentation generated with pdoc --math linked to JavaScript files from polyfill.io.
The polyfill.io CDN has been sold and now serves malicious code.
Users who produce documentation with math mode should update immediately. All other users are unaffected.
This issue has been fixed in pdoc 14.5.1.
https://github.com/mitmproxy/pdoc/pull/703 https://sansec.io/research/polyfill-supply-chain-attack
pdoc < 14.5.1Upgrade to a patched release:
pdoc 14.5.1Field changes observed since this record was first indexed.