CVE-2025-56648

MEDIUM

parcel < 1.10.3 - Origin Validation Error via XMLHTTPRequest

Title source: llm
STIX 2.1

Description

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (3)
parcel/reporter-dev-server 1.6.1npm
parceljs/parcel 2.0.0 alpha0
parceljs/parcel < 1.10.3
Published Sep 17, 2025
Tracked Since Feb 18, 2026