PT-2025-38252 · Parcel · Parcel

R4356Th

·

Published

2025-09-17

·

Updated

2025-12-30

·

CVE-2025-56648

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions parcel versions 2.0.0-alpha and earlier
Description A security issue exists in Parcel that allows malicious websites to send XMLHTTPRequests to the application's development server and read the response, potentially leading to source code theft when developers visit these websites. This occurs during developer activity while working on a project with the Parcel dev server running.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-56648
GHSA-QM9P-F9J5-W83W

Affected Products

Parcel