cbcvebase.
CVE-2026-14620
published 2026-07-03

CVE-2026-14620: webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that…

PriorityP434medium4.7CVSS 3.1
AVNACLPRNUIRSCCNINAL
EXPLOIT
EPSS
0.52%
42.0th percentile
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the visit. An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer's machine. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: none.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-24lightspeed-rhel8
ansible-automation-platform-25lightspeed-rhel8
ansible-automation-platform-26gateway-rhel9
ansible-automation-platform-26lightspeed-rhel9
ansible-automation-platform-27gateway-rhel9
ansible-automation-platform-27lightspeed-rhel9
ansible-automation-platformautomation-portal
clusterlabspcs
container-native-virtualizationkubevirt-console-plugin
container-native-virtualizationkubevirt-console-plugin-rhel9
discoverydiscovery-ui-rhel9
gatekeepergatekeeper-rhel9
grafanagrafana
openshift-lightspeedlightspeed-console-plugin-419-rhel9
openshift-lightspeedlightspeed-console-plugin-pf5-rhel9
openshift-lightspeedlightspeed-console-plugin-rhel9
openshift-pipelinespipelines-console-plugin-pf5-rhel9
openshift-pipelinespipelines-console-plugin-rhel8
openshift-pipelinespipelines-console-plugin-rhel9
openshift-pipelinespipelines-hub-ui-rhel8
openshift-pipelinespipelines-hub-ui-rhel9
openshift-service-meshkiali-operator-bundle
openshift-service-meshkiali-ossmc-rhel9
openshift-service-meshkiali-rhel9
openshift-service-meshkiali-rhel9-operator

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L
vendor_redhat4.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.