vite
npm16 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting vitepage 1 of 1
- CVE-2022-35204MEDIUMCVSS 4.3EG 4.3✓ Fixed in 3.0.0-beta.42022-08-18
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
- CVE-2023-34092HIGHCVSS 7.5EG 7.5✓ Fixed in 4.3.92023-06-01
Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the V…
- CVE-2023-49293MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.0.52023-12-04
Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (`…
- CVE-2024-23331HIGHCVSS 7.5EG 7.5✓ Fixed in 5.0.122024-01-19
Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. T…
- CVE-2024-31207MEDIUMCVSS 5.9EG 5.9✓ Fixed in 5.2.62024-04-04
Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been pat…
- CVE-2024-45811MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.1.82024-09-17
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL b…
- CVE-2024-45812MEDIUMCVSS 6.4EG 6.4✓ Fixed in 5.1.82024-09-17
Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. The DOM Clobbering gadget in the module …
- CVE-2025-24010MEDIUMCVSS 6.5EG 6.5✓ Fixed in 6.0.92025-01-20
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket conn…
- CVE-2025-31486MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.5.122025-04-03
Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass.…
- CVE-2025-32395MEDIUMCVSS 6.0EG 0.0✓ Fixed in 4.5.132025-04-10
Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP 1.1 spec (RFC 9112) do…
- CVE-2025-46565MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.3.42025-05-01
Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps …
- CVE-2025-58752MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.1.52025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server …
- CVE-2025-62522MEDIUMCVSS 6.0EG 0.0✓ Fixed in 5.4.212025-10-20
Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, f…
- CVE-2026-39363HIGHCVSS 7.5EG 7.5✓ Fixed in 6.4.22026-04-07
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…
- CVE-2026-39364HIGHCVSS 7.5EG 7.5✓ Fixed in 7.3.22026-04-07
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query param…
- CVE-2026-39365MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.4.22026-04-07
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segme…
Check whether vite is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for vite CVEs against the assets you own.
Start Free Scan →