OsVault/npm/webpack
npm2 critical

webpack

73 known vulnerabilities · 2 critical · 2 high

CVE-2024-43788MEDIUM

Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

Published Aug 27, 2024
CVE-2025-68157

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

Published Feb 5, 2026
CVE-2025-68458

webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

Published Feb 5, 2026
CVE-2023-28154CRITICAL

Cross-realm object access in Webpack 5

Published Mar 13, 2023
CVE-2020-24855MEDIUM

easywebpack-cli Path Traversal vulnerability

Published Dec 15, 2022
CVE-2025-30359

webpack-dev-server users' source code may be stolen when they access a malicious web site

Published Jun 4, 2025
CVE-2025-30360

webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser

Published Jun 4, 2025
MAL-2022-1502

Malicious code in bender-webpack (npm)

Published Jun 20, 2022
MAL-2022-2780

Malicious code in erserwebpackplugin (npm)

Published Aug 19, 2022
MAL-2022-160

Malicious code in @bynder-private/persistgraphql-webpack-plugin (npm)

Published Jun 20, 2022
CVE-2022-37601CRITICAL

Prototype pollution in webpack loader-utils

Published Oct 13, 2022
MAL-2022-2186

Malicious code in copywebpackplugxin (npm)

Published Aug 19, 2022
MAL-2022-4633

Malicious code in mitui-util-webpack (npm)

Published Jun 20, 2022
MAL-2022-6741

Malicious code in ug-lifjjs-webpack-plugin (npm)

Published Aug 19, 2022
MAL-2022-2444

Malicious code in deps-json-webpack-plugin (npm)

Published Jun 20, 2022
MAL-2024-10889

Malicious code in webpack-support-multi-domain-plugin (npm)

Published Nov 22, 2024
MAL-2024-10890

Malicious code in webpack-svg-spirit-import (npm)

Published Nov 22, 2024
MAL-2022-7099

Malicious code in webpack-3undle-analyr (npm)

Published Aug 19, 2022
CVE-2018-14732HIGH

Missing Origin Validation in webpack-dev-server

Published Jan 4, 2019
MAL-2023-1468

Malicious code in ynf-dx-webpack-plugins (npm)

Published Aug 14, 2023
MAL-2025-260

Malicious code in webpack-next (npm)

Published Jan 20, 2025
MAL-2025-48553

Malicious code in webpack-compilejsx (npm)

Published Oct 22, 2025
MAL-2025-38

Malicious code in alchemy-web3-webpack-example (npm)

Published Jan 8, 2025
MAL-2023-1342

Malicious code in webpack-cli.legacy (npm)

Published May 1, 2023
CVE-2024-29180HIGH

Path traversal in webpack-dev-middleware

Published Mar 21, 2024
MAL-2025-154

Malicious code in ad-shield-webpack (npm)

Published Jan 20, 2025
MAL-2024-1573

Malicious code in bootstrap-npm-webpack (npm)

Published Jun 11, 2024
MAL-2023-54

Malicious code in @playgami/portal-webpack (npm)

Published Jan 9, 2023
MAL-2025-318

Malicious code in webpack-extensive-lodash-replacement-plugin (npm)

Published Jan 21, 2025
MAL-2022-3105

Malicious code in fork-ts-checker-webpack-lugin-alt (npm)

Published Aug 19, 2022
MAL-2025-48538

Malicious code in webpack-css-load-branch (npm)

Published Oct 21, 2025
MAL-2022-7100

Malicious code in webpack-cil (npm)

Published Aug 19, 2022
MAL-2022-7101

Malicious code in webpack-dev-fixture (npm)

Published Nov 14, 2022
MAL-2022-6969

Malicious code in vr-webpack (npm)

Published Jun 20, 2022
MAL-2025-48441

Malicious code in webpack-loadcss (npm)

Published Oct 17, 2025
MAL-2025-6200

Malicious code in simple-line-icons-webpack (npm)

Published Jul 22, 2025
MAL-2024-10745

Malicious code in theme-webpack (npm)

Published Nov 17, 2024
MAL-2022-5110

Malicious code in optimiecssassetswebpackplugin (npm)

Published Aug 19, 2022
MAL-2025-1038

Malicious code in html-webpack-plugin-v4 (npm)

Published Feb 3, 2025
MAL-2025-7078

Malicious code in @amber-team/webpack-config (npm)

Published Aug 14, 2025
MAL-2022-157

Malicious code in @bugbounty-automation/deps-json-webpack-plugin (npm)

Published Jun 20, 2022
MAL-2022-44

Malicious code in 7np-webpack-pugin (npm)

Published Aug 19, 2022
MAL-2022-7103

Malicious code in webpack-vue-config (npm)

Published Jun 20, 2022
MAL-2022-7104

Malicious code in webpack.js.org (npm)

Published Jun 20, 2022
MAL-2022-7290

Malicious code in xo-webpack-config (npm)

Published Jun 20, 2022
MAL-2025-192693

Malicious code in airslate-dep-webpack (npm)

Published Dec 22, 2025
MAL-2026-70

Malicious code in @shop-cicd/webpack-package-artifact (npm)

Published Jan 6, 2026
MAL-2022-5475

Malicious code in progressbr-webpack-plugin (npm)

Published Aug 19, 2022
MAL-2022-7102

Malicious code in webpack-old (npm)

Published Jun 20, 2022
MAL-2022-3005

Malicious code in feiendlyerrorswebpackplugin (npm)

Published Aug 19, 2022
MAL-2023-1343

Malicious code in webpack-dev-server.legacy (npm)

Published May 1, 2023
MAL-2022-5398

Malicious code in polaris-example-webpack (npm)

Published Jun 20, 2022
MAL-2024-9415

Malicious code in webpack-i18n-tools (npm)

Published Oct 17, 2024
MAL-2024-9416

Malicious code in webpack4types (npm)

Published Oct 17, 2024
MAL-2024-10888

Malicious code in webpack-insert-sentry-plugin (npm)

Published Nov 22, 2024
MAL-2025-347

Malicious code in text-unicode-webpack (npm)

Published Jan 22, 2025
MAL-2022-6079

Malicious code in shared-library-webpack-plugin (npm)

Published Jun 20, 2022
MAL-2025-3784

Malicious code in webpack-cli-v4 (npm)

Published May 14, 2025
MAL-2024-1596

Malicious code in core-webpack (npm)

Published Jun 12, 2024
MAL-2025-1039

Malicious code in html-webpack-plugin-v5 (npm)

Published Feb 3, 2025
MAL-2023-141

Malicious code in braze-webpack-sample (npm)

Published Jul 14, 2023
MAL-2025-3783

Malicious code in webpack-cli-4 (npm)

Published May 14, 2025
MAL-2022-1835

Malicious code in casesensitijepathswebpackplugin (npm)

Published Aug 19, 2022
MAL-2022-1916

Malicious code in cleanwebpackmplugin (npm)

Published Aug 19, 2022
MAL-2025-319

Malicious code in webpack-inline-constant-exports-plugin (npm)

Published Jan 21, 2025
MAL-2025-48012

Malicious code in webpack-dev-serve-middleware (npm)

Published Oct 7, 2025
MAL-2025-191154

Malicious code in webpack-loader-httpfile (npm)

Published Nov 24, 2025
MAL-2025-48085

Malicious code in webpack-loader-css-branch (npm)

Published Oct 8, 2025
MAL-2026-918

Malicious code in webpack-vite (npm)

Published Feb 16, 2026
MAL-2025-48311

Malicious code in webpack-css-branch-loader (npm)

Published Oct 10, 2025
MAL-2025-48349

Malicious code in webpack-load-css-branch (npm)

Published Oct 13, 2025
MAL-2025-6305

Malicious code in react-server-dom-webpack-experimental (npm)

Published Jul 25, 2025
MAL-2025-4663

Malicious code in minimal-ts-webpack (npm)

Published Jun 3, 2025
Check your entire dependency tree at onceRun dependency scan →