Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-28154

31
FAUCET Score

CVE-2023-28154 is a critical vulnerability in Webpack 5, specifically versions prior to 5.76.0, where the ImportParserPlugin.js component fails to properly handle magic comments, leading to cross-realm object access. This allows an attacker to gain access to the real global object by controlling a property of an untrusted object. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low attack complexity, and can result in high impacts to confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0.0, < 5.76.0CPE matchmatch criteria
cpe:2.3:a:webpack.js:webpack:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.41%
Probability of exploitation in next 30 days
EPSS Percentile
69.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0141 is in the 57th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: webpackFixed in: 5.76.0
redhatpatch availablevia redhat_api
Product: OpenShift-Pipelines-1.10-RHEL-8Fixed in: openshift-pipelines/pipelines-hub-ui-rhel8:v1.10.5-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs-0:0.11.3-4.el9_1.3
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-theia-rhel8-container
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: OpenShift Developer Tools and ServicesFixed in: odo
redhatno patchvia redhat_api
Product: Red Hat A-MQ OnlineFixed in: webpack
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-monitoring-plugin-rhel8

Vendor Advisories (3)

microsoft2023-Mar/CVE-2023-28154Critical

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Mar 14, 2023
npmGHSA-hc6q-2mpp-qw7jcritical

Cross-realm object access in Webpack 5

Mar 13, 2023
redhatCVE-2023-28154Important

webpack: avoid cross-realm objects

Mar 13, 2023

References

github.com / webpack/webpack/compare/v5.75.0...v5.76.0
PatchProduct
github.com / webpack/webpack/pull/16500
Patch
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/AU7BOXTBK3KDYSWH67ASZ22TUIOZ3X5G
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PPSAXUTXBCCTAHTCX5BUR4YVP25XALQ3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/U2AFCM6FFE3LRYI6KNEQWKMXMQOBZQ2D