Back

LOW

Vite's `server.fs` settings were not applied to HTML files

Published Sep 8, 2025

Description

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.

Affected products

Remediation

Red Hat statement

This issue is rated Low severity as it only allows unintended disclosure of HTML files and does not impact system integrity or availability. Exploitation requires specific conditions: the application must explicitly expose the Vite dev server to the network (via --host or server.host), and must be configured as appType: 'spa' (default) or appType: 'mpa'. The vulnerability also affects the preview server, which may serve HTML files outside of the designated output directory.

Red Hat mitigation

* Avoid exposing the dev or preview server to untrusted networks. * Disable or restrict HTML fallback handlers if possible. * Carefully review server.fs.allow / server.fs.deny settings to minimize exposure.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 8, 2025
Updated Sep 9, 2025
Reserved Sep 4, 2025
CISA Vulnrichment
Updated Sep 9, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 8, 2025
GHSA-JQFW-VQ24-V9C3