CVE-2025-56648 Details
Description
npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.
An origin validation error vulnerability has been identified in Parcel versions through 2.0.0-alpha. This issue allows malicious websites to send XMLHttpRequests to the application's development server. When developers visit these sites, the response can be intercepted and used to steal source code.
Developers can apply the patch available in Parcel's GitHub repository. If unable to do so, it is advised to avoid visiting untrusted websites while the Parcel development server is running. If necessary, use a proxy to block requests to localhost.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| parceljs parcel | <= 1.10.3 2.0.0 alpha0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 26, 2026 | CVE Modified | [email protected] |
| Sep 26, 2025 | Initial Analysis | [email protected] |
| Sep 17, 2025 | CVE Modified | CISA-ADP |
| Sep 17, 2025 | New CVE Received | [email protected] |