{"id":"CVE-2024-38526","aliases":["GHSA-5vgj-ggm4-fg62","PYSEC-2026-1764"],"url":"https://o3.security/vulnerability/CVE-2024-38526","summary":"pdoc embeds link to malicious CDN if math mode is enabled","details":"pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.","published":"2024-06-25T23:53:54.677Z","modified":"2026-08-12T03:51:27.861503861Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L/E:H/RL:O/RC:C/MC:N/MI:N/MA:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"pdoc","fixedVersion":"14.5.1"}],"fix":{"url":"https://github.com/mitmproxy/pdoc/pull/703","label":"mitmproxy/pdoc#703"},"references":[{"type":"WEB","url":"https://sansec.io/research/polyfill-supply-chain-attack"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/polyfillio-in-pdoc-cve-2024-38526"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38526.json"},{"type":"ADVISORY","url":"https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38526"},{"type":"FIX","url":"https://github.com/mitmproxy/pdoc/pull/703"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.861503861Z"}}