webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
Moderate severity
GitHub Reviewed
Published
Jul 3, 2026
in
webpack/webpack-dev-server
•
Updated Jul 20, 2026
Description
Published by the National Vulnerability Database
Jul 3, 2026
Published to the GitHub Advisory Database
Jul 20, 2026
Reviewed
Jul 20, 2026
Last updated
Jul 20, 2026
Impact
The internal
/webpack-dev-server/open-editorand/webpack-dev-server/invalidateendpoints perform state-changing actions on anyGETrequest, without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger them cross-origin with no interaction beyond the visit.An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root (e.g.
~/.ssh/config). The file's contents are not returned to the attacker. Repeated requests can also spawn editor processes and force recompilations, degrading the developer's machine.Patches
Fixed in
webpack-dev-server5.2.6 by rejecting cross-site requests to the/webpack-dev-server/open-editorand/webpack-dev-server/invalidateendpoints (see PR #5698).Workarounds
None
References