Description
pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5vgj-ggm4-fg62 | pdoc embeds link to malicious CDN if math mode is enabled |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mitmproxy
Mitmproxy pdoc |
|
| CPEs | cpe:2.3:a:mitmproxy:pdoc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mitmproxy
Mitmproxy pdoc |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:53:15.493Z
Reserved: 2024-06-18T16:37:02.728Z
Link: CVE-2024-38526
Updated: 2024-08-02T04:12:25.740Z
Status : Awaiting Analysis
Published: 2024-06-26T00:15:10.703
Modified: 2024-11-21T09:26:11.483
Link: CVE-2024-38526
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA