GHSA-f5vj-f2hx-8m93

Suggest an improvement
Source
https://github.com/advisories/GHSA-f5vj-f2hx-8m93
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-f5vj-f2hx-8m93/GHSA-f5vj-f2hx-8m93.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-f5vj-f2hx-8m93
Aliases
Downstream
CGA (46)
MINI (6)
Published
2026-07-20T22:01:56Z
Modified
2026-07-20T22:15:20Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L CVSS Calculator
Summary
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
Details

Impact

The internal /webpack-dev-server/open-editor and /webpack-dev-server/invalidate endpoints perform state-changing actions on any GET request, without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger them cross-origin with no interaction beyond the visit.

An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root (e.g. ~/.ssh/config). The file's contents are not returned to the attacker. Repeated requests can also spawn editor processes and force recompilations, degrading the developer's machine.

Patches

Fixed in webpack-dev-server 5.2.6 by rejecting cross-site requests to the /webpack-dev-server/open-editor and /webpack-dev-server/invalidate endpoints (see PR #5698).

Workarounds

None

Database specific
{
    "cwe_ids": [
        "CWE-352",
        "CWE-749"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-20T22:01:56Z",
    "nvd_published_at": "2026-07-03T17:16:53Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / webpack-dev-server

Package

Name
webpack-dev-server
View open source insights on deps.dev
Purl
pkg:npm/webpack-dev-server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.6

Database specific

last_known_affected_version_range
"<= 5.2.5"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-f5vj-f2hx-8m93/GHSA-f5vj-f2hx-8m93.json"