Vite's `server.fs` settings were not applied to HTML files
Published Sep 8, 2025
2.3
LOWCVSS 4.0
EPSS 0.61%
Description
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
Affected products
-
- Version < 5.4.20StatusaffectedConstraints-
- Version >= 6.0.0, < 6.3.6StatusaffectedConstraints-
- Version >= 7.0.0, < 7.0.7StatusaffectedConstraints-
- Version >= 7.1.0, < 7.1.5StatusaffectedConstraints-
- Version
No data.
Red Hat Ansible Automation Platform 2
automation-controller
Fix deferred
Red Hat Ansible Automation Platform 2
automation-eda-controller
Fix deferred
Red Hat Ansible Automation Platform 2
automation-gateway
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
org.keycloak-keycloak-parent
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.keycloak-keycloak-parent
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/traefik-rhel9
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-agent-rhel8
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-all-in-one-rhel8
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-collector-rhel8
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-es-index-cleaner-rhel8
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-es-rollover-rhel8
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-ingester-rhel8
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-operator-bundle
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-query-rhel8
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-rhel8-operator
Fix deferred
Red Hat OpenShift distributed tracing 3
rhosdt/tempo-jaeger-query-rhel8
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | automation-controller | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | automation-eda-controller | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | automation-gateway | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | org.keycloak-keycloak-parent | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.keycloak-keycloak-parent | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-agent-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-all-in-one-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-collector-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-es-index-cleaner-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-es-rollover-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-ingester-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-operator-bundle | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-query-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-rhel8-operator | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-jaeger-query-rhel8 | Fix deferred | n/a |
vite
npm
Introduced 7.1.0 Fixed 7.1.5vite
npm
Introduced 7.0.0 Fixed 7.0.7vite
npm
Introduced 6.0.0 Fixed 6.3.6vite
npm
Introduced 0 Fixed 5.4.20
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | vite | 7.1.0 | 7.1.5 |
| npm | vite | 7.0.0 | 7.0.7 |
| npm | vite | 6.0.0 | 6.3.6 |
| npm | vite | 0 | 5.4.20 |
Remediation
Red Hat statement
This issue is rated Low severity as it only allows unintended disclosure of HTML files and does not impact system integrity or availability. Exploitation requires specific conditions: the application must explicitly expose the Vite dev server to the network (via --host or server.host), and must be configured as appType: 'spa' (default) or appType: 'mpa'. The vulnerability also affects the preview server, which may serve HTML files outside of the designated output directory.
Red Hat mitigation
* Avoid exposing the dev or preview server to untrusted networks. * Disable or restrict HTML fallback handlers if possible. * Carefully review server.fs.allow / server.fs.deny settings to minimize exposure.
References (11)
- https://access.redhat.com/security/cve/CVE-2025-58752 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2393983 Issue Tracking
- https://github.com/advisories/GHSA-jqfw-vq24-v9c3 Advisory
- https://github.com/vitejs/vite/blob/v7.1.5/packages/vite/CHANGELOG.md
- https://github.com/vitejs/vite/commit/0ab19ea9fcb66f544328f442cf6e70f7c0528d5f x_refsource_MISCPatch
- https://github.com/vitejs/vite/commit/14015d794f69accba68798bd0e15135bc51c9c1e x_refsource_MISCPatch
- https://github.com/vitejs/vite/commit/482000f57f56fe6ff2e905305100cfe03043ddea x_refsource_MISCPatch
- https://github.com/vitejs/vite/commit/6f01ff4fe072bcfcd4e2a84811772b818cd51fe6 x_refsource_MISCPatch
- https://github.com/vitejs/vite/security/advisories/GHSA-jqfw-vq24-v9c3 exploitx_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-58752
- https://www.cve.org/CVERecord?id=CVE-2025-58752
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-58752 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2393983 | Issue Tracking | |
| https://github.com/advisories/GHSA-jqfw-vq24-v9c3 | Advisory | |
| https://github.com/vitejs/vite/blob/v7.1.5/packages/vite/CHANGELOG.md | ||
| https://github.com/vitejs/vite/commit/0ab19ea9fcb66f544328f442cf6e70f7c0528d5f | x_refsource_MISCPatch | |
| https://github.com/vitejs/vite/commit/14015d794f69accba68798bd0e15135bc51c9c1e | x_refsource_MISCPatch | |
| https://github.com/vitejs/vite/commit/482000f57f56fe6ff2e905305100cfe03043ddea | x_refsource_MISCPatch | |
| https://github.com/vitejs/vite/commit/6f01ff4fe072bcfcd4e2a84811772b818cd51fe6 | x_refsource_MISCPatch | |
| https://github.com/vitejs/vite/security/advisories/GHSA-jqfw-vq24-v9c3 | exploitx_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-58752 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-58752 |
Change history (0)
No recorded changes yet.