Origin validation error in webpack-dev-server - CVE-2025-30360
Published: July 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect Origin validation in webpack-dev-server/lib/Server.js. A remote attacker can trick the application into connecting to a malicious website with a non-Chromium browser and and share its source code with it, a.k.a. cross-site WebSocket hijacking.
Affected software
watsonx Orchestrate Developer Edition
Maximo Application Suite - Edge Data Collector
watsonx.data
IBM Cognos Controller
How to mitigate CVE-2025-30360
watsonx Orchestrate Developer Edition - update to 1.15.0
watsonx.data - update to 2.3.1
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.23, 9.0.15, 9.1.5
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
External References
- https://github.com/webpack/webpack-dev-server/blob/55220a800ba4e30dbde2d98785ecf4c80b32f711/lib/Server.js#L3113-L3127
- https://github.com/webpack/webpack-dev-server/commit/5c9378bb01276357d7af208a0856ca2163db188e
- https://github.com/webpack/webpack-dev-server/commit/72efaab83381a0e1c4914adf401cbd210b7de7eb
- https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-9jgg-88mc-972h