ZeroHour

CVE-2025-56648

PoC ×2
CVSS 3.1
6.5 medium
EPSS
<1%p15
Published
()
Modified
Description

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

Vendors
parceljs
Products
parcel
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.