{"id":"GHSA-5vgj-ggm4-fg62","summary":"pdoc embeds link to malicious CDN if math mode is enabled","details":"### Impact\n\nDocumentation generated with `pdoc --math` linked to JavaScript files from polyfill.io.\nThe polyfill.io CDN has been sold and now serves malicious code.\n\nUsers who produce documentation with math mode should update immediately. All other users are unaffected.\n\n### Patches\n\nThis issue has been fixed in pdoc 14.5.1.\n\n### References\n\nhttps://github.com/mitmproxy/pdoc/pull/703\nhttps://sansec.io/research/polyfill-supply-chain-attack\n\n### Timeline\n\n- **[2024-06-25]** https://sansec.io/research/polyfill-supply-chain-attack is published.\n- **[2024-06-25 20:54 UTC]** Issue reported to the pdoc project by @adhintz.\n- **[2024-06-25 21:33 UTC]** Patched version released.\n- **[2024-06-25 21:37 UTC]** Security advisory published.\n- **[2024-06-25 23:49 UTC]** CVE-2024-38526 assigned by GitHub.","aliases":["CVE-2024-38526","PYSEC-2026-1764"],"modified":"2026-07-07T17:57:02.093875031Z","published":"2024-06-25T22:23:30Z","database_specific":{"nvd_published_at":"2024-06-26T00:15:10Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-06-25T22:23:30Z"},"references":[{"type":"WEB","url":"https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38526"},{"type":"WEB","url":"https://github.com/mitmproxy/pdoc/pull/703"},{"type":"WEB","url":"https://github.com/mitmproxy/pdoc/commit/726b8f2e365fe8afeb3604a7c73d19b460395d58"},{"type":"PACKAGE","url":"https://github.com/mitmproxy/pdoc"},{"type":"WEB","url":"https://sansec.io/research/polyfill-supply-chain-attack"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/polyfillio-in-pdoc-cve-2024-38526"}],"affected":[{"package":{"name":"pdoc","ecosystem":"PyPI","purl":"pkg:pypi/pdoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"14.5.1"}]}],"versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.19","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.2.0","0.2.1","0.2.2","0.2.3","0.2.4","0.3.0","0.3.1","0.3.2","0.4","0.4.1","1.0.0","1.0.1","1.1.0","10.0.0","10.0.1","10.0.2","10.0.3","10.0.4","11.0.0","11.1.0","11.2.0","12.0.0","12.0.1","12.0.2","12.1.0","12.2.0","12.2.1","12.2.2","12.3.0","12.3.1","13.0.0","13.0.1","13.1.0","13.1.1","14.0.0","14.1.0","14.2.0","14.3.0","14.4.0","14.5.0","2.0.0","3.0.0","3.0.1","4.0.0","5.0.0","6.0.0","6.1.0","6.1.1","6.2.0","6.3.0","6.3.1","6.3.2","6.4.0","6.4.1","6.4.2","6.4.3","6.4.4","6.5.0","6.6.0","7.0.0","7.0.1","7.0.2","7.0.3","7.1.0","7.1.1","7.2.0","7.3.0","7.3.1","7.4.0","8.0.0","8.0.1","8.1.0","8.2.0","8.3.0","9.0.0","9.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-5vgj-ggm4-fg62/GHSA-5vgj-ggm4-fg62.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L"}]}