Medium severity6.5NVD Advisory· Published Sep 17, 2025· Updated Jun 17, 2026
CVE-2025-56648
CVE-2025-56648
Description
npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@parcel/reporter-dev-servernpm | >= 1.6.1, < 2.16.4 | 2.16.4 |
Affected products
4- npm/parceldescription
Patches
Vulnerability mechanics
References
7- gist.github.com/R4356th/41f468def606b2406e36f7193f5322b8nvdExploitWEB
- github.com/parcel-bundler/parcel/issues/10216nvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-qm9p-f9j5-w83wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-56648ghsaADVISORY
- github.com/parcel-bundler/parcel/commit/4bc56e3242a85491c7edf589966e9b44c6330c49nvdWEB
- github.com/parcel-bundler/parcel/commit/9e2f6f1377123cff3b82f6dde4e20336efc846a1ghsaWEB
- github.com/parcel-bundler/parcel/pull/10138ghsaWEB
News mentions
0No linked articles in our index yet.