6.5

CVE-2025-56648

Exploit
npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ParceljsParcel Version <= 1.10.3
ParceljsParcel Version2.0.0 Updatealpha0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.124
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://gist.github.com/R4356th/41f468def606b2406e36f7193f5322b8
Exploit
https://github.com/parcel-bundler/parcel/discussions/10089
Issue Tracking
https://github.com/parcel-bundler/parcel/issues/10216
Exploit
Issue Tracking
https://github.com/parcel-bundler/parcel/commit/4bc56e3242a85491c7edf589966e9b44c6330c49