Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-56648

Опубликовано: 17 сент. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

npm parcel has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rustFix deferred
Red Hat Enterprise Linux 9rustFix deferred
Red Hat JBoss Enterprise Application Platform 8org.jboss.hal-hal-parentNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.jboss.hal-hal-parentNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2396209parcel: Parcel Origin Validation Error

EPSS

Процентиль: 1%
0.00008
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
7 месяцев назад

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.

CVSS3: 6.5
github
7 месяцев назад

Parcel has an Origin Validation Error vulnerability

EPSS

Процентиль: 1%
0.00008
Низкий

6.5 Medium

CVSS3