Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2022-37601: Webpack Loader-Utils Allows Arbitrary Function Execution

CVE-2022-37601 · published 1 day ago
Summary

A security issue in Webpack Loader-Utils allows attackers to execute arbitrary JavaScript code. This affects all versions before 1.4.1 and 2.0.3. To fix this issue, update to version 1.4.1 or 2.0.3 or later.

What to do
  • Update evilebottnawi loader-utils to version 2.0.3.
  • Update evilebottnawi loader-utils to version 1.4.1.
  • Update rootio @rootio/loader-utils to version 0.2.17-root.io.1.
  • Update rootio @rootio/loader-utils to version 0.2.17-root.io.2.
  • Update loader-utils to version 0.2.17-aikido.2.
  • Update rootio @rootio/loader-utils to version 2.0.3-root.io.2.
  • Update loader-utils to version 2.0.3-aikido.2.
Affected software
Ecosystem VendorProductAffected versions
npm evilebottnawi loader-utils >= 2.0.0, < 2.0.3
< 1.4.1
Fix: upgrade to 2.0.3
webpack.js loader-utils < 1.4.1
>= 2.0.0, < 2.0.3
cpe:2.3:a:webpack.js:loader-utils:*:*:*:*:*:*:*:*
debian debian_linux 10.0
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Root:npm rootio @rootio/loader-utils < 0.2.17-root.io.1
< 0.2.17-root.io.2
< 2.0.3-root.io.2
Fix: upgrade to 0.2.17-root.io.1
Root:npm loader-utils < 0.2.17-aikido.2
< 2.0.3-aikido.2
Fix: upgrade to 0.2.17-aikido.2
Original advisory text
CVE-2022-37601 in loader-utils - Patched by Root
Root has patched CVE-2022-37601 in the loader-utils package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 3%
Type
CWE-1321Prototype Pollution
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta