Executive brief
Parcel, a popular web application build tool, contains a vulnerability in its development server that could allow malicious websites to steal a developer's source code. If a developer visits a compromised or malicious website while their Parcel development server is running, that site can silently request and read files from the developer's local machine. This could lead to the exposure of proprietary code, configuration files, and sensitive credentials.
Technical details
An Origin Validation Error (CWE-346) exists in the @parcel/reporter-dev-server package. The development server fails to properly validate the 'Origin' header of incoming requests, allowing cross-origin resource sharing (CORS) from any site. A remote attacker can exploit this by enticing a developer with an active dev server to visit a malicious webpage; the webpage can then use XMLHTTPRequests to read the application's source code and other assets served by Parcel. This vulnerability is patched in version 2.16.4, which also introduces a `--no-cors` flag to explicitly disable CORS headers.
Affected products
- Parcel @parcel/reporter-dev-server >= 1.6.1, <= 2.16.3
Timeline
- 2025-09-17: disclosed
- 2025-09-17: advisory
- 2025-09-18: other: GitHub Reviewed