Parceljs maintains a JavaScript bundler and build tool with a focused product footprint that has gained adoption in web development workflows, presenting a toolchain-level attack surface. The observed vulnerability pattern centers on information-disclosure and origin-validation weaknesses, reflecting the build system's exposure to dependency management and artifact handling. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Parceljs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14731HIGH An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server | Sep 21, 2018 | 7.5 | 26 | NO | NO |
CVE-2025-56648MEDIUM npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the res | Sep 17, 2025 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Parceljs.
Media articles that mention a CVE ID that affects a product developed by Parceljs — matched by CVE ID, not by vendor name.