VYPR
Critical severityNVD Advisory· Published Mar 13, 2023· Updated Feb 27, 2025

CVE-2023-28154

CVE-2023-28154

Description

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
webpacknpm
>= 5.0.0, < 5.76.05.76.0

Affected products

7

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.