The Lab · 2026-04-08 17:27:16 · GitHub Issues
A critical security vulnerability in the widely used webpack-dev-server tool exposes developers to source code theft. The flaw, tracked as CVE-2025-30359, allows malicious actors to steal source code when a developer accesses a compromised or malicious web server. This represents a direct threat to intellectual propert...
The Lab · 2026-04-08 18:27:24 · GitHub Issues
A critical security vulnerability in the widely used webpack-dev-server tool allows malicious websites to steal the source code of applications running on a developer's local machine. The flaw, tracked as CVE-2025-30359, stems from the server's handling of classic script requests, which are not subject to the same-orig...
The Lab · 2026-04-15 15:22:44 · GitHub Issues
A major version update for the widely used webpack-dev-server package is being flagged as a security priority, driven by a newly disclosed vulnerability, CVE-2025-30359. The automated dependency management PR highlights a jump from version 3.11.2 to 5.0.0, a significant leap that underscores the severity of the underly...