vite
npm22 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting vitepage 1 of 1
- CVE-2022-35204MEDIUMCVSS 4.3EG 4.3fixed in 2.9.13 or 3.0.0-beta.4, by version range2022-08-18
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
- CVE-2023-34092HIGHCVSS 7.5EG 7.5fixed in 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3 or 4.3.9, by version range2023-06-01
Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the V…
- CVE-2023-49293MEDIUMCVSS 6.1EG 6.1fixed in 4.4.12, 4.5.1 or 5.0.5, by version range2023-12-04
vulnerable: 4.5.0
Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (`…
- CVE-2024-23331HIGHCVSS 7.5EG 7.5fixed in 2.9.17, 3.2.8, 4.5.2 or 5.0.12, by version range2024-01-19
Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. T…
- CVE-2024-31207MEDIUMCVSS 5.9EG 5.9fixed in 2.9.18, 3.2.10, 4.5.3, 5.0.13, 5.1.7 or 5.2.6, by version range2024-04-04
Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been pat…
- CVE-2024-45811MEDIUMCVSS 4.8EG 4.8fixed in 5.4.6, 5.3.6, 5.2.14, 4.5.4, 3.2.11 or 5.1.8, by version range2024-09-17
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL b…
- CVE-2024-45812MEDIUMCVSS 6.4EG 6.4fixed in 5.4.6, 5.3.6, 5.2.14, 4.5.4, 3.2.11 or 5.1.8, by version range2024-09-17
Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. The DOM Clobbering gadget in the module …
- CVE-2024-52011HIGHCVSS 8.3EG 8.3fixed in 5.4.92026-06-01
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Win…
- CVE-2025-24010MEDIUMCVSS 6.5EG 6.5fixed in 6.0.9, 5.4.12 or 4.5.6, by version range2025-01-20
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket conn…
- CVE-2025-30208HIGHCVSS 5.3EG 8.3fixed in 6.2.3, 6.1.2, 6.0.12, 5.4.15 or 4.5.10, by version range2025-03-24
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the…
- CVE-2025-31125CRITICALCVSS 5.3EG 9.0⚠ KEVfixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16 or 4.5.11, by version range2025-03-31
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option…
- CVE-2025-31486MEDIUMCVSS 5.3EG 5.9fixed in 6.2.5, 6.1.4, 6.0.14, 5.4.17 or 4.5.12, by version range2025-04-03
Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass.…
- CVE-2025-32395MEDIUMCVSS 6.0EG 6.0fixed in 6.2.6, 6.1.5, 6.0.15, 5.4.18 or 4.5.13, by version range2025-04-10
Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP 1.1 spec (RFC 9112) do…
- CVE-2025-46565MEDIUMCVSS 5.3EG 5.3fixed in 6.3.4, 6.2.7, 6.1.6, 5.4.19 or 4.5.14, by version range2025-05-01
Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps …
- CVE-2025-58751MEDIUMCVSS 5.3EG 5.3fixed in 7.1.5, 7.0.7, 6.3.6 or 5.4.20, by version range2025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly e…
- CVE-2025-58752MEDIUMCVSS 5.3EG 5.3fixed in 7.1.5, 7.0.7, 6.3.6 or 5.4.20, by version range2025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server …
- CVE-2025-62522MEDIUMCVSS 6.0EG 6.0fixed in 7.1.11, 7.0.8, 6.4.1 or 5.4.21, by version range2025-10-20
Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, f…
- CVE-2026-39363HIGHCVSS 7.5EG 7.5fixed in 8.0.5, 7.3.2 or 6.4.2, by version range2026-04-07
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…
- CVE-2026-39364HIGHCVSS 7.5EG 7.5fixed in 8.0.5 or 7.3.2, by version range2026-04-07
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query param…
- CVE-2026-39365MEDIUMCVSS 5.3EG 5.3fixed in 8.0.5, 7.3.2 or 6.4.2, by version range2026-04-07
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segme…
- CVE-2026-53571HIGHCVSS 7.5EG 7.5fixed in 8.0.16, 7.3.5 or 6.4.3, by version range2026-06-15
Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensi…
- CVE-2026-53632MEDIUMCVSS 5.5EG 5.5fixed in 8.0.16, 7.3.5 or 6.4.3, by version range2026-06-15
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attemp…
Check whether vite is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for vite CVEs against the assets you own.
Book a Demo →