CVE-2025-30360: webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Source code may be stolen when you access a malicious web site with non-Chromium based browser.
References
- github.com/advisories/GHSA-9jgg-88mc-972h
- github.com/webpack/webpack-dev-server
- github.com/webpack/webpack-dev-server/blob/55220a800ba4e30dbde2d98785ecf4c80b32f711/lib/Server.js
- github.com/webpack/webpack-dev-server/commit/72efaab83381a0e1c4914adf401cbd210b7de7eb
- github.com/webpack/webpack-dev-server/commit/d2575ad8dfed9207ed810b5ea0ccf465115a2239
- github.com/webpack/webpack-dev-server/security/advisories/GHSA-9jgg-88mc-972h
- nvd.nist.gov/vuln/detail/CVE-2025-30360
Code Behaviors & Features
Detect and mitigate CVE-2025-30360 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →