webpack-dev-server users' source code may be stolen when they access a malicious web site
- Severity:
- Medium
Description
Source code may be stolen when you access a malicious web site.
Recommendation
Update the webpack-dev-server
package to the latest compatible version. Followings are version details:
- Affected version(s): <= 5.2.0
- Patched version(s): 5.2.1
References
Related Issues
- webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browse - CVE-2025-30360
- matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal - CVE-2024-50336
- Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service - CVE-2022-35204
- Unauthenticated Denial of Service in the octokit/webhooks library (GHSA-pwfr-8pq7-x9qv) 2 - CVE-2023-50728
- Tags:
- npm
- webpack-dev-server
Anything's wrong? Let us know Last updated on June 04, 2025