The Lab · 2026-03-27 05:27:03 · GitHub Issues
A critical security update for the widely-used JavaScript module bundler Webpack patches a DOM Clobbering vulnerability that can lead to cross-site scripting (XSS) attacks. The flaw, tracked as CVE-2024-43788, resides in Webpack's `AutoPublicPathRuntimeModule`. This module is a core component for determining the public...
The Lab · 2026-04-15 09:22:40 · GitHub Issues
A critical security vulnerability in Webpack, the ubiquitous JavaScript module bundler, has been patched in version 5.94.0. The flaw, tracked as CVE-2024-43788, is a DOM Clobbering weakness within Webpack's `AutoPublicPathRuntimeModule`. This vulnerability creates a pathway for cross-site scripting (XSS) attacks, poten...
The Lab · 2026-05-12 15:48:24 · GitHub Issues
A critical DOM Clobbering vulnerability has been identified in Webpack's `AutoPublicPathRuntimeModule`, potentially enabling Cross-Site Scripting (XSS) attacks in applications that rely on affected versions of the bundler. The flaw, tracked as CVE-2024-43788 and catalogued under GHSA-4vvj-4cpr-p986, affects webpack ver...
The Lab · 2026-05-13 03:48:21 · GitHub Issues
A significant security vulnerability has been identified in Webpack 5's `AutoPublicPathRuntimeModule`, exposing applications to Cross-Site Scripting (XSS) attacks through a technique known as DOM Clobbering. Tracked as CVE-2024-43788 and catalogued under GHSA-4vvj-4cpr-p986, the flaw affects all webpack versions up to ...