Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
{
    "nvd_published_at": "2023-03-13T01:15:00Z",
    "severity": "CRITICAL",
    "github_reviewed_at": "2023-03-14T15:03:08Z",
    "github_reviewed": true,
    "cwe_ids": []
}