WhisperX tag archive

#Webpack

This page collects WhisperX intelligence signals tagged #Webpack. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (18)

The Lab · 2026-03-26 09:27:10 · GitHub Issues

1. CVE-2025-10437: Eksagate Webpack 관리 시스템에 심각한 SQL 인젝션 취약점 발견 (CVSS 9.8)

Eksagate Electronic Engineering and Computer Industry Trade Inc.의 'Webpack Management System'에서 심각한 SQL 인젝션 취약점(CVE-2025-10437)이 공개적으로 식별됐다. 이 취약점은 CVSS 9.8의 위험 등급을 부여받았으며, 공격자가 네트워크를 통해 인증 없이 시스템에 접근해 데이터의 기밀성, 무결성, 가용성을 모두 높은 수준으로 침해할 수 있는 위험을 내포하고 있다. 2025년 11월 19일 이하 버전의 소프트웨어가 영향을 받는 것으로 확인됐다. 취약점의 기술적 원인은 'SQL 명...

The Lab · 2026-03-26 14:27:38 · GitHub Issues

2. Security Alert: High-Severity RCE Vulnerability in serialize-javascript Build Dependency

A high-severity Remote Code Execution (RCE) vulnerability has been identified in the `serialize-javascript` package, a transitive dependency for projects using `copy-webpack-plugin`. The vulnerability, tracked as GHSA-5c6j-r48x-rmvq, affects `serialize-javascript` versions 7.0.2 and earlier. While classified as a build...

The Lab · 2026-03-27 00:27:19 · GitHub Issues

3. Vulnerable Webpack Plugin Exposes DimaMend/V-Achilles Repository to 5 High-Severity Flaws

A critical security scan has flagged the `optimize-css-assets-webpack-plugin` version 6.0.1 as a vector for five distinct vulnerabilities within the DimaMend/V-Achilles GitHub repository. The most severe flaw carries a CVSS score of 7.5, indicating a high-risk exposure. The vulnerable library is directly integrated int...

The Lab · 2026-03-27 07:26:57 · GitHub Issues

4. High-Severity CVE-2026-33891 Detected in node-forge Library, Exposes Webpack & React Toolchains

A high-severity vulnerability, CVE-2026-33891, has been detected in the widely used `node-forge` JavaScript cryptography library, version 1.3.3. This flaw creates a direct security exposure within a critical dependency chain for modern web development, specifically impacting projects built with React and Webpack. The v...

The Lab · 2026-03-28 04:27:01 · GitHub Issues

5. sw-precache-webpack-plugin 0.11.5 发现 23 个漏洞,最高严重性达 9.8 分 [可被利用]

一个关键的 Webpack 插件被发现存在严重的安全漏洞。在 `sw-precache-webpack-plugin-0.11.5.tgz` 中,安全扫描揭示了 23 个漏洞,其中最高严重性评分为 9.8 分(CVSS v3),且部分漏洞被标记为“可被利用”。该插件用于在 Webpack 构建流程中集成 Service Worker,其依赖链中的缺陷直接暴露了使用它的应用程序。 漏洞详情显示,问题主要存在于传递依赖项中。例如,`minimist-1.2.0.tgz` 存在一个评分为 9.8 的严重漏洞(CVE-2021-44906),而 `lodash.template-4.4.0.tgz` 则存在另一个评分为 9.1 的严重漏洞...

The Lab · 2026-04-09 01:27:07 · GitHub Issues

6. terser-webpack-plugin 4.2.3 曝 14 项漏洞,最高严重性达 8.8,可被利用

一个广泛使用的 JavaScript 构建工具链组件被曝存在严重安全漏洞。根据 GitHub 依赖项扫描报告,`terser-webpack-plugin` 的 4.2.3 版本包含 14 个已识别的漏洞,其中最高严重性评分为 8.8(CVSS 评分),且被标记为“可被利用”。该插件是 webpack 生态中的关键依赖,用于压缩和混淆前端代码,其漏洞可能影响大量依赖此工具链的现代 Web 应用项目。 报告显示,漏洞存在于多个依赖路径中,包括 `/achilles-frontend/package.json` 和 `/baak-vizualization/package.json`。其中一项高严重性漏洞(CVE-2026-27904...

The Lab · 2026-04-10 00:39:43 · GitHub Issues

7. Critical Supply Chain Risk: webpack-plugin-injector 1.0.6 Exposes Projects to 10 High-Severity Vulnerabilities

A critical security alert has been issued for the widely used `webpack-plugin-injector` npm package, version 1.0.6. The library contains 10 distinct vulnerabilities, with the highest severity rated a critical 9.8 on the CVSS scale. Crucially, these vulnerabilities are flagged as 'reachable,' meaning the exploitable cod...

The Lab · 2026-04-10 00:39:46 · GitHub Issues

8. Terser-Webpack-Plugin 4.2.3 Exposes Critical Supply Chain Risk with 15 Vulnerabilities

A widely used JavaScript build tool, terser-webpack-plugin version 4.2.3, has been flagged with 15 distinct vulnerabilities, including one rated with a critical CVSS score of 8.8. The security scan reveals a deeply embedded supply chain risk, as these flaws are not only present but are also classified as 'reachable,' m...

The Lab · 2026-04-10 00:39:51 · GitHub Issues

9. OpenTok Video Call Center: 27 Vulnerabilities in webpack-dev-server, Including Critical 8.6 CVSS Flaw

A critical security exposure has been identified within the OpenTok Video Call Center project. The repository's dependency on `webpack-dev-server-4.11.1.tgz` introduces 27 distinct vulnerabilities, with the highest severity scoring a dangerous 8.6 on the CVSS scale. This development server package, essential for updati...

The Lab · 2026-04-10 00:39:52 · GitHub Issues

10. Critical Security Flaw in webpack-bundle-analyzer 3.9.0: 6 Vulnerabilities, Including 9.8 CVSS Score, Found Reachable

A critical security exposure has been identified in the widely used `webpack-bundle-analyzer` version 3.9.0, with six distinct vulnerabilities flagged as reachable within the dependency chain. The most severe of these carries a maximum CVSS severity score of 9.8, indicating a critical risk that could allow for remote c...

The Lab · 2026-04-15 09:22:40 · GitHub Issues

11. Webpack 5.94.0 Patches Critical DOM Clobbering Flaw (CVE-2024-43788) Enabling XSS Attacks

A critical security vulnerability in Webpack, the ubiquitous JavaScript module bundler, has been patched in version 5.94.0. The flaw, tracked as CVE-2024-43788, is a DOM Clobbering weakness within Webpack's `AutoPublicPathRuntimeModule`. This vulnerability creates a pathway for cross-site scripting (XSS) attacks, poten...

The Lab · 2026-04-15 15:22:46 · GitHub Issues

12. Critical Security Flaw in webpack-dev-middleware Exposes Developer Machines to File Access

A severe vulnerability in the widely used webpack-dev-middleware package allows attackers to access any file on a developer's local machine. The flaw, tracked as CVE-2024-29180, stems from insufficient URL validation before the middleware returns a local file. This creates a direct path for unauthorized access to sensi...

The Lab · 2026-04-18 15:22:34 · GitHub Issues

13. Shopware Administration Exposed: Critical 9.8 CVSS Vulnerability in webpack-dev-server Dependency Chain

A critical security exposure has been identified within the Shopware 6 administration panel's build toolchain. The dependency `webpack-dev-server-3.11.3.tgz` introduces a chain of 42 vulnerabilities into the system, with the most severe flaw scoring a maximum 9.8 on the CVSS scale. This high-risk package is directly re...

The Lab · 2026-04-18 15:22:36 · GitHub Issues

14. Critical 9.8 CVSS Vulnerability in webpack-cli Dependency Chain Exposes Build Pipeline

A critical vulnerability with a maximum CVSS score of 9.8 has been flagged as reachable within the dependency chain of `webpack-cli-3.3.12.tgz`. The finding, identified as CVE-2022-37601, resides in the transitive dependency `loader-utils-1.4.0.tgz`. Its reachable status indicates the vulnerable code path is likely exp...

The Lab · 2026-04-18 15:22:39 · GitHub Issues

15. Critical 9.8-Severity Vulnerabilities Found in Shopware 6 Administration Build Chain via html-loader

A critical security exposure has been identified within the build chain of Shopware 6's administration interface. The flagged dependency, `html-loader-0.5.5.tgz`, contains seven vulnerabilities, with the most severe scoring a maximum 9.8 on the CVSS scale. This high-risk package is embedded in the Nuxt component librar...

The Lab · 2026-05-10 12:01:39 · GitHub Issues

16. Webpack 5.104.1 Patches SSRF Vulnerability in buildHttp allowedUris Bypass

A security-critical update to webpack addresses a vulnerability that could allow attackers to bypass URL allow-lists and trigger server-side request forgery (SSRF) during build processes. The patch, released as webpack version 5.104.1, resolves CVE-2025-68458 (GHSA-8fgc-7cc6-rx7x), which affects the experimental `build...

The Lab · 2026-05-12 15:48:24 · GitHub Issues

17. Webpack AutoPublicPathRuntimeModule DOM Clobbering Vulnerability Exposes Applications to XSS — CVE-2024-43788

A critical DOM Clobbering vulnerability has been identified in Webpack's `AutoPublicPathRuntimeModule`, potentially enabling Cross-Site Scripting (XSS) attacks in applications that rely on affected versions of the bundler. The flaw, tracked as CVE-2024-43788 and catalogued under GHSA-4vvj-4cpr-p986, affects webpack ver...

The Lab · 2026-05-13 03:48:21 · GitHub Issues

18. Critical DOM Clobbering XSS Vulnerability Found in Webpack 5 AutoPublicPathRuntimeModule — CVE-2024-43788

A significant security vulnerability has been identified in Webpack 5's `AutoPublicPathRuntimeModule`, exposing applications to Cross-Site Scripting (XSS) attacks through a technique known as DOM Clobbering. Tracked as CVE-2024-43788 and catalogued under GHSA-4vvj-4cpr-p986, the flaw affects all webpack versions up to ...