Skip to content

pdoc embeds link to malicious CDN if math mode is enabled

High
mhils published GHSA-5vgj-ggm4-fg62 Jun 25, 2024

Package

pip pdoc (pip)

Affected versions

< 14.5.1

Patched versions

14.5.1

Description

Impact

Documentation generated with pdoc --math linked to JavaScript files from polyfill.io.
The polyfill.io CDN has been sold and now serves malicious code.

Users who produce documentation with math mode should update immediately. All other users are unaffected.

Patches

This issue has been fixed in pdoc 14.5.1.

References

#703
https://sansec.io/research/polyfill-supply-chain-attack

Timeline

Severity

High

CVE ID

CVE-2024-38526

Weaknesses

Credits