CVE-2025-56648: Medium severity npm Parcel vulnerability
npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56648?
CVE-2025-56648 is classified as a high-severity vulnerability due to the potential for source code theft.
How do I fix CVE-2025-56648?
To fix CVE-2025-56648, update npm Parcel to a version later than 2.0.0-alpha.
What does CVE-2025-56648 exploit?
CVE-2025-56648 exploits an Origin Validation Error allowing malicious websites to send XMLHTTPRequests to the application’s development server.
Who is affected by CVE-2025-56648?
Developers using npm Parcel version 2.0.0-alpha and earlier are affected by CVE-2025-56648.
What can attackers do with CVE-2025-56648?
Attackers can potentially steal source code from the application when the developer visits a malicious website.