PT-2025-23649 · Unknown · Webpack-Dev-Server

Sapphi-Red

·

Published

2025-06-03

·

Updated

2025-11-21

·

CVE-2025-30360

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions webpack-dev-server versions prior to 5.2.1
Description The issue allows an attacker to obtain source code via a method similar to that used to exploit a previously reported vulnerability. This is possible because webpack-dev-server always allows IP address Origin headers, enabling websites served on IP addresses to connect via WebSocket. The Origin header is checked to prevent Cross-site WebSocket hijacking.
Recommendations For versions prior to 5.2.1, update to version 5.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebSocket connection to prevent potential exploitation.

Exploit

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2025-30360
GHSA-9JGG-88MC-972H

Affected Products

Webpack-Dev-Server