webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Source code may be stolen when you access a malicious web site with non-Chromium based browser.
Source code may be stolen when you access a malicious web site with non-Chromium based browser.
Source code may be stolen when you access a malicious web site. Source code may be stolen when you use output.iife: false and access a malicious web site.
An issue was discovered in lib/Server.js in webpack-dev-server. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://:/ connection from any origin.