CVE Vulnerabilities

CVE-2025-56648

Origin Validation Error

Published: Sep 17, 2025 | Modified: Jan 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the applications development server and read the response to steal source code when developers visit them.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
ParcelParceljs*1.10.3 (including)
ParcelParceljs2.0.0-alpha0 (including)2.0.0-alpha0 (including)

References