{"id":"PYSEC-2026-1764","summary":"pdoc embeds link to malicious CDN if math mode is enabled","details":"### Impact\n\nDocumentation generated with `pdoc --math` linked to JavaScript files from polyfill.io.\nThe polyfill.io CDN has been sold and now serves malicious code.\n\nUsers who produce documentation with math mode should update immediately. All other users are unaffected.\n\n### Patches\n\nThis issue has been fixed in pdoc 14.5.1.\n\n### References\n\nhttps://github.com/mitmproxy/pdoc/pull/703\nhttps://sansec.io/research/polyfill-supply-chain-attack\n\n### Timeline\n\n- **[2024-06-25]** https://sansec.io/research/polyfill-supply-chain-attack is published.\n- **[2024-06-25 20:54 UTC]** Issue reported to the pdoc project by @adhintz.\n- **[2024-06-25 21:33 UTC]** Patched version released.\n- **[2024-06-25 21:37 UTC]** Security advisory published.\n- **[2024-06-25 23:49 UTC]** CVE-2024-38526 assigned by GitHub.","aliases":["CVE-2024-38526","GHSA-5vgj-ggm4-fg62"],"modified":"2026-07-07T17:47:18.155731612Z","published":"2026-07-07T14:34:35.434298Z","references":[{"type":"WEB","url":"https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38526"},{"type":"WEB","url":"https://github.com/mitmproxy/pdoc/pull/703"},{"type":"WEB","url":"https://github.com/mitmproxy/pdoc/commit/726b8f2e365fe8afeb3604a7c73d19b460395d58"},{"type":"PACKAGE","url":"https://github.com/mitmproxy/pdoc"},{"type":"WEB","url":"https://sansec.io/research/polyfill-supply-chain-attack"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/polyfillio-in-pdoc-cve-2024-38526"},{"type":"PACKAGE","url":"https://pypi.org/project/pdoc"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5vgj-ggm4-fg62"}],"affected":[{"package":{"name":"pdoc","ecosystem":"PyPI","purl":"pkg:pypi/pdoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"14.5.1"}]}],"versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.19","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.2.0","0.2.1","0.2.2","0.2.3","0.2.4","0.3.0","0.3.1","0.3.2","0.4","0.4.1","1.0.0","1.0.1","1.1.0","10.0.0","10.0.1","10.0.2","10.0.3","10.0.4","11.0.0","11.1.0","11.2.0","12.0.0","12.0.1","12.0.2","12.1.0","12.2.0","12.2.1","12.2.2","12.3.0","12.3.1","13.0.0","13.0.1","13.1.0","13.1.1","14.0.0","14.1.0","14.2.0","14.3.0","14.4.0","14.5.0","2.0.0","3.0.0","3.0.1","4.0.0","5.0.0","6.0.0","6.1.0","6.1.1","6.2.0","6.3.0","6.3.1","6.3.2","6.4.0","6.4.1","6.4.2","6.4.3","6.4.4","6.5.0","6.6.0","7.0.0","7.0.1","7.0.2","7.0.3","7.1.0","7.1.1","7.2.0","7.3.0","7.3.1","7.4.0","8.0.0","8.0.1","8.1.0","8.2.0","8.3.0","9.0.0","9.0.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pdoc/PYSEC-2026-1764.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L"}]}