High severity7.2OSV Advisory· Published Jun 26, 2024· Updated Jun 17, 2026
CVE-2024-38526
CVE-2024-38526
Description
pdoc provides API Documentation for Python Projects. Documentation generated with pdoc --math linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pdocPyPI | < 14.5.1 | 14.5.1 |
Affected products
6- ghsa-coords5 versionspkg:pypi/pdocpkg:rpm/opensuse/ghc-pandoc&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/netpbm&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ghc-pandoc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/ghc-pandoc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7
< 14.5.1+ 4 more
- (no CPE)range: < 14.5.1
- (no CPE)range: < 3.1.11.1-150500.11.6.1
- (no CPE)range: < 11.7.0-1.1
- (no CPE)range: < 3.1.11.1-150500.11.6.1
- (no CPE)range: < 3.1.11.1-150500.11.6.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-5vgj-ggm4-fg62ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-38526ghsaADVISORY
- github.com/mitmproxy/pdoc/commit/726b8f2e365fe8afeb3604a7c73d19b460395d58ghsaWEB
- github.com/mitmproxy/pdoc/pull/703nvdWEB
- github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62nvdWEB
- sansec.io/research/polyfill-supply-chain-attacknvdWEB
- www.vicarius.io/vsociety/posts/polyfillio-in-pdoc-cve-2024-38526nvdWEB
News mentions
0No linked articles in our index yet.