← Zurück zur CVE-Suche

CVE-2026-14620

webpack-dev-server

Beschreibung

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server-s own page. Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the visit. An attacker can open an arbitrary existing local file in the developer-s editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer-s machine. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: none.

CVSS 4.7EPSS 0.149%Risiko 0.48
Quelle öffnen
Veröffentlicht
2026-07-03 17:16:53
Betroffene Versionen
<=5.2.5
Typ
Webanwendung
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L