Skip to content

Upgrade webpack-dev-server to ^5.2.1 address CVE-2025-30360 #17095

Open
@n8ores

Description

@n8ores

react-scripts uses webpack-dev-server version 4.6.0 this contains a vulnerability CVE-2025-30360

This has been addressed in webpack-dev-server 5.2.1 and up. I suggest upgrading the dependency on webpack-dev-server to ^5.2.1 or preferably the latest 5.2.2 to address.

Details

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based browser. The Origin header is checked to prevent Cross-site WebSocket hijacking from happening, which was reported by CVE-2018-14732. But webpack-dev-server always allows IP address Origin headers. This allows websites that are served on IP addresses to connect WebSocket. An attacker can obtain source code via a method similar to that used to exploit CVE-2018-14732. Version 5.2.1 contains a patch for the issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions