CVE-2025-56648

Publication date

2025-09-17 00:00:00

Family

mitre

State

PUBLISHED

Description

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the applications development server and read the response to steal source code when developers visit them.