webpack-dev-server Version: <=3.1.14
[x] This is a bug
https://www.npmjs.com/advisories/725
=== npm audit security report ===
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Manual Review โ
โ Some vulnerabilities require your attention to resolve โ
โ โ
โ Visit https://go.npm.me/audit-guide for additional guidance โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ High โ Missing Origin Validation โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Package โ webpack-dev-server โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Patched in โ >=3.1.11 โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Dependency of โ webpack-dev-server [dev] โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Path โ webpack-dev-server โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ More info โ https://nodesecurity.io/advisories/725 โ
โโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
I have the same issue. I have tried: npm audit fix, manual update of webpack-dev-server to version 3.1.14, removal of node_modules and package-lock.json. Nothing of this helps.
With webpack-dev-server version 3.1.10 initially installed npm audit fix says
+ [email protected]
updated 1 package in 3.517s
fixed 1 of 1 vulnerability...
But then npm audit still reports about 1 high severity vulnerability:
~~~
=== npm audit security report ===
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Manual Review โ
โ Some vulnerabilities require your attention to resolve โ
โ โ
โ Visit https://go.npm.me/audit-guide for additional guidance โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ High โ Missing Origin Validation โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Package โ webpack-dev-server โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Patched in โ >=3.1.11 โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Dependency of โ webpack-dev-server [dev] โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Path โ webpack-dev-server โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ More info โ https://nodesecurity.io/advisories/725 โ
โโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
found 1 high severity vulnerability in 9001 scanned packages
1 vulnerability requires manual review. See the full report for details.
~~~
It's probably caused by #1604
Still getting this issue despite the fact that I am on v3.1.14. Reinstalling does nothing

The npmjs advisory is currently inconsistent and there is no 3.1.x patch that npm audit will allow.
https://npm.community/t/advisory-725-inconsistently-marks-affected-versions/4333
Not working with [email protected]
@antimodern Don't worry, you're not being hacked. As you can see, it's trying to access a local address - most likely your own computer. The reason it fails to do so is because you've disconnected from the network, and your computer lost its IP address.
I'm getting the same issue, updating to 3.1.14 doesnt solve the issue, npm audit still returns the vulnerability after updating
there seems to be a typo in the vulnerability database: https://npm.community/t/npm-audit-sweems-to-get-semver-wrong/4352/4
there seems to be a typo in the vulnerability database: https://npm.community/t/npm-audit-sweems-to-get-semver-wrong/4352/4
You saved my rest of the day
there seems to be a typo in the vulnerability database: https://npm.community/t/npm-audit-sweems-to-get-semver-wrong/4352/4
how can we get this typo fixed? some builds require npm audit returning a clean bill of health
how can we get this typo fixed? some builds require npm audit returning a clean bill of health
Not sure, but the link in my previous post is a bug-report at NPM, so maybe voting on it will help it getting resolved faster.
how can we get this typo fixed? some builds require npm audit returning a clean bill of health
Not sure, but the link in my previous post is a bug-report at NPM, so maybe voting on it will help it getting resolved faster.
done, thanks
Either wepack and create a new version with 3.2.0 like that would help?
On Wed, 2 Jan 2019 at 8:53 PM, Charles Freduah notifications@github.com
wrote:
how can we get this typo fixed? some builds require npm audit returning a
clean bill of healthNot sure, but the link in my previous post is a bug-report at NPM, so
maybe voting on it will help it getting resolved faster.done, thanks
โ
You are receiving this because you commented.
Reply to this email directly, view it on GitHub
https://github.com/webpack/webpack-dev-server/issues/1615#issuecomment-450891741,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ApssRpxYQLaW0cLasw6nAvOm62wKYmDqks5u_M8NgaJpZM4Zlnt5
.>
Thanks & Regards,Manish AggarwalMb: +919802551120
Skype: manish.aggarwalm
Either wepack and create a new version with 3.2.0 like that would help?
I would just wait for the NPM audit team to fix this. This is a widely used dependency so I'm sure they'll have it fixed in a few hours.
Either wepack and create a new version with 3.2.0 like that would help?
probably not, unless they are releasing version 3.110.1 ;)
Okay thanks let them do before its late
On Wed, 2 Jan 2019 at 9:00 PM, Syed Farhan notifications@github.com wrote:
Either wepack and create a new version with 3.2.0 like that would help?
I would just wait for the NPM audit team to fix this. This is widely used
dependency so I'm sure they'll have it fixed in a few hours.โ
You are receiving this because you commented.
Reply to this email directly, view it on GitHub
https://github.com/webpack/webpack-dev-server/issues/1615#issuecomment-450893487,
or mute the thread
https://github.com/notifications/unsubscribe-auth/ApssRl7Zn_QJkj6H6cBJptPV75A7reemks5u_NCAgaJpZM4Zlnt5
.>
Thanks & Regards,Manish AggarwalMb: +919802551120
Skype: manish.aggarwalm
I think it is fixed, the audit passes for me.
Cool, thank you all!
I'm still getting the error. Can someone please help me how to resolve this issue? Thanks.

Hi @tshravan86. You must update the version of "webpack-dev-server" to 3.1.14 in the following files: package-lock.json and package.json. in all occurrences. Finally, run "npm update"
it works for me
@nelson1212 note that npm update will update _all_ your package to their latest versions, which might not be what you want
If you want to do a more targeted update (and you tend to save exact version numbers in your package.json), here is what I did:
webpack-dev-server version in package.jsonpackage-lock.jsonnode_modules directorynpm i to re-fetch everything and write a new package-lock.jsonAlternatively, if you use caret notation for your dependencies and want to be certain that _only_ webpack-dev-server is updated, follow what @nelson1212 suggested with the following change:
package.json and package-lock.json as @nelson1212 describednode_modulesnpm i@nelson1212 Thanks for your help, it worked. @chimericdream thanks for your information. Need to change the version number at package-lock.json as well. Thanks once again.
@nelson1212 Thanks for your help, it worked. @chimericdream thanks for your information. Need to change the version number at
package-lock.jsonas well. Thanks once again.
My pleasure
Most helpful comment
there seems to be a typo in the vulnerability database: https://npm.community/t/npm-audit-sweems-to-get-semver-wrong/4352/4