Back

LOW

Vite middleware may serve files starting with the same name with the public directory

Published Sep 8, 2025

Description

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.

Affected products

Remediation

Red Hat statement

Red Hat Customers should be aware that the underlying vulnerability originates in the sirv package, which is responsible for serving static files. Vite uses sirv internally to serve content during development, which means projects using Vite were also exposed to the issue. While sirv is technically the component containing the flaw, the upstream Vite project issued the CVE/advisory because the impact was most visible and widespread through Vite’s ecosystem. In practice, this means that both direct consumers of sirv and Vite users are affected, but the CVE was filed under Vite Project by it's maintainers. This vulnerability is rated Low severity because exploitation requires several specific conditions: the Vite dev server must be exposed to the network (via --host or server.host), the application must use the public directory feature, and a symlink must exist inside that public directory to point to the target. These conditions make exploitation unlikely in typical production environments, and the impact is limited to disclosure of files outside the intended directory. The vulnerability does not permit code execution, file modification, or denial of service.

Red Hat mitigation

* Avoid exposing the Vite dev server (--host / server.host) to untrusted networks. * Do not allow symlinks inside the public directory that reference files outside of it.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 8, 2025
Updated Sep 9, 2025
Reserved Sep 4, 2025
CISA Vulnrichment
Updated Sep 9, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 8, 2025
ENISA EUVD
Assigner GitHub_M
Published Sep 8, 2025
Updated Sep 9, 2025
Exploited since n/a
EUVD-2025-27181 GHSA-G4JQ-H2W9-997C