Intel

AIKIDO-2025-10649

webpack-dev-server is vulnerable to Origin Validation Error

Origin Validation ErrorCVE-2025-30360 Published Sep 18, 2025

45

Medium Risk

This Affects:

jswebpack-dev-server
0.0.1 - 5.2.0
Fixed in 5.2.1
Are you affected? Scan for Free

TL;DR

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based browser. The Origin header is checked to prevent Cross-site WebSocket hijacking from happening, which was reported by CVE-2018-14732. But webpack-dev-server always allows IP address Origin headers. This allows websites that are served on IP addresses to connect WebSocket. An attacker can obtain source code via a method similar to that used to exploit CVE-2018-14732. Version 5.2.1 contains a patch for the issue.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

webpack-dev-server is vulnerable to Origin Validation Error in versions 0.0.1 - 5.2.0.

How to fix this

Upgrade the webpack-dev-server library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform