CVE-2026-14620Disclosure(webpack.js / webpack-dev-server)

LOWCVSS 4.7 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch webpack.js webpack-dev-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the visit. An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer's machine. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: none.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352CWE-749

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webpack-dev-server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
webpack-dev-server

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-03: 3Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 307-03
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in webpack-dev-server@5.2.6 just released! Patches CVE-2026-14620: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-f5vj-f2hx-8m93

    Post summary

    The tweet announces a patch for CVE-2026-14620, a CSRF flaw in webpack-dev-server, and provides a link to a GitHub security advisory.

    00010203
    5.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14620 webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perfor… https://www.cve.org/CVERecord?id=CVE-2026-14620 ----- Traducción: CVE-2026-14620 web… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-14620, detailing exposed internal development endpoints in webpack-dev-server 5.2.5 and earlier, without indicating exploitation tools, activity, or patches.

    0000046
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14620 webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perfor… https://www.cve.org/CVERecord?id=CVE-2026-14620

    Post summary

    The post announces CVE‑2026‑14620, detailing exposed internal endpoints in webpack‑dev‑server and providing basic technical information about the flaw.

    00000735
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebpack.jswebpack-dev-server---

Explore more