CVE-2025-56648 — npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal s — CVE Database · The Intelligence Room