Descripción
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server-s own page. Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the visit. An attacker can open an arbitrary existing local file in the developer-s editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer-s machine. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: none.
CVSS 4.7EPSS 0.149%Riesgo 0.48
Ver fuente- Publicación
- 2026-07-03 17:16:53
- Versiones afectadas
- <=5.2.5
- Tipo
- Aplicación web
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L