This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Sebastian Beltran
bjohansebas.me
did:plc:bb2guqtpnbo42adajblrvduf
š New advisory: webpack-dev-server (CVE-2026-9595).
A proxy with context / and ws: true intercepts the HMR WebSocket, leaking cookies to the backend.
ā
Patched in 5.2.5
https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79
2026-06-15T14:51:05.673Z