Product
A CSRF vulnerability (CVE-2026-14620) in webpack-dev-server 5.2.5 allows unauthenticated cross-origin requests to trigger the launchEditor() function, potentially enabling remote command execution via arbitrary local file paths.