Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qm9p-f9j5-w83w

Опубликовано: 17 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Parcel has an Origin Validation Error vulnerability

parcel versions 1.6.1 and above have an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them. Version 2.16.4 supports a --no-cors option which disables CORS headers in the dev server.

Пакеты

Наименование

@parcel/reporter-dev-server

npm
Затронутые версииВерсия исправления

>= 1.6.1, <= 2.16.3

2.16.4

EPSS

Процентиль: 15%
0.00236
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 6.5
redhat
11 месяцев назад

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

CVSS3: 6.5
nvd
11 месяцев назад

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

EPSS

Процентиль: 15%
0.00236
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-346