GHSA-jwq7-6j4r-2f92

Suggest an improvement
Source
https://github.com/advisories/GHSA-jwq7-6j4r-2f92
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-jwq7-6j4r-2f92/GHSA-jwq7-6j4r-2f92.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jwq7-6j4r-2f92
Aliases
Published
2025-09-11T14:22:40Z
Modified
2025-09-12T01:42:18Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Prebid.js NPM package briefly compromised
Details

Impact

NPM users of prebid 10.9.2. The malicious code attempts to redirect crypto transactions on the site to the attackers' wallet.

Patches

10.10.0 is solved

References

https://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack

Database specific
{
    "cwe_ids":  [
        "CWE-506"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-09-11T14:22:40Z",
    "nvd_published_at":  "2025-09-09T23:15:37Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / prebid.js

Package

Affected ranges

Type
SEMVER
Events
Introduced
10.9.2
Fixed
10.10.0

Affected versions

10.*
10.9.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-jwq7-6j4r-2f92/GHSA-jwq7-6j4r-2f92.json"