- EPSS 0.03%
- Veröffentlicht 20.10.2025 19:57:13
- Zuletzt bearbeitet 21.10.2025 19:31:25
Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied...
CVE-2025-58752
- EPSS 0.03%
- Veröffentlicht 08.09.2025 22:56:58
- Zuletzt bearbeitet 17.09.2025 16:12:20
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the netw...
CVE-2025-58751
- EPSS 2.09%
- Veröffentlicht 08.09.2025 22:52:45
- Zuletzt bearbeitet 17.09.2025 16:21:36
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the V...
CVE-2025-46565
- EPSS 0.11%
- Veröffentlicht 01.05.2025 17:20:29
- Zuletzt bearbeitet 02.10.2025 15:40:34
Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps explicitly ...
- EPSS 0.03%
- Veröffentlicht 10.04.2025 13:25:19
- Zuletzt bearbeitet 11.04.2025 15:39:52
Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP 1.1 spec (RFC 9112) does not allo...
CVE-2025-31486
- EPSS 2.59%
- Veröffentlicht 03.04.2025 18:24:39
- Zuletzt bearbeitet 07.04.2025 14:18:34
Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypas...
CVE-2025-31125
- EPSS 3.61%
- Veröffentlicht 31.03.2025 17:15:43
- Zuletzt bearbeitet 24.09.2025 15:45:00
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affec...
CVE-2025-30208
- EPSS 88.12%
- Veröffentlicht 24.03.2025 17:03:40
- Zuletzt bearbeitet 23.09.2025 14:39:29
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypass...
CVE-2025-24010
- EPSS 0.03%
- Veröffentlicht 20.01.2025 16:15:28
- Zuletzt bearbeitet 19.09.2025 18:35:59
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. Th...
CVE-2024-45812
- EPSS 0.19%
- Veröffentlicht 17.09.2024 20:15:06
- Zuletzt bearbeitet 20.09.2024 12:30:51
Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. The DOM Clobbering gadget in the module can lead to...