CVE-2025-56648

MEDIUM

Parcel < 1.10.3 - Origin Validation Error

Title source: rule
STIX 2.1

Description

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 0.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (3)
parcel/reporter-dev-server 1.6.1npm
parceljs/parcel 2.0.0 alpha0
parceljs/parcel < 1.10.3
Published Sep 17, 2025
Tracked Since Feb 18, 2026