Vitejs

Vite

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 22.06.2026 16:10:58
  • Zuletzt bearbeitet 23.06.2026 16:04:55

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files th...

  • EPSS 0.32%
  • Veröffentlicht 22.06.2026 15:54:09
  • Zuletzt bearbeitet 23.06.2026 15:44:39

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM aut...

  • EPSS 0.53%
  • Veröffentlicht 01.06.2026 17:17:43
  • Zuletzt bearbeitet 02.06.2026 14:04:23

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by sup...

Exploit
  • EPSS 0.91%
  • Veröffentlicht 07.04.2026 19:13:50
  • Zuletzt bearbeitet 30.04.2026 18:34:09

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the UR...

Exploit
  • EPSS 1.72%
  • Veröffentlicht 07.04.2026 19:12:47
  • Zuletzt bearbeitet 30.04.2026 18:34:57

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such ...

Exploit
  • EPSS 2.29%
  • Veröffentlicht 07.04.2026 19:10:44
  • Zuletzt bearbeitet 30.04.2026 18:34:19

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket e...

  • EPSS 1.03%
  • Veröffentlicht 20.10.2025 19:57:13
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 08.09.2025 22:56:58
  • Zuletzt bearbeitet 17.09.2025 16:12:20

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the netw...

Exploit
  • EPSS 1.18%
  • Veröffentlicht 08.09.2025 22:52:45
  • Zuletzt bearbeitet 17.09.2025 16:21:36

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the V...

Exploit
  • EPSS 1.08%
  • Veröffentlicht 01.05.2025 17:20:29
  • Zuletzt bearbeitet 02.10.2025 15:40:34

Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps explicitly ...