6.5
CVE-2025-56648
- EPSS 0.22%
- Veröffentlicht 17.09.2025 19:15:46
- Zuletzt bearbeitet 26.01.2026 17:16:11
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.124 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
https://gist.github.com/R4356th/41f468def606b2406e36f7193f5322b8
https://github.com/parcel-bundler/parcel/discussions/10089
https://github.com/parcel-bundler/parcel/issues/10216
https://github.com/parcel-bundler/parcel/commit/4bc56e3242a85491c7edf589966e9b44c6330c49