Vitejs / Vite
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-53571 | Vite: `server.fs.deny` bypass on Windows alternate paths | HIGH | 8.2 | Jun 22, 2026 |
| CVE-2026-53632 | NTLMv2 hash disclosure via UNC path handling on Windows | MEDIUM | 5.5 | Jun 22, 2026 |
| CVE-2024-52011 | launch-editor vulnerable to command injection via the crafted request on Windows | HIGH | 7.5 | Jun 1, 2026 |
| CVE-2026-39365 | Vite has a Path Traversal in Optimized Deps `.map` Handling | MEDIUM | 6.3 | Apr 7, 2026 |
| CVE-2026-39364 | Vite has a `server.fs.deny` bypass with queries | HIGH | 8.2 | Apr 7, 2026 |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | HIGH | 8.2 | Apr 7, 2026 |
| CVE-2025-62522 | vite allows server.fs.deny bypass via backslash on Windows | MEDIUM | 6.0 | Oct 20, 2025 |
| CVE-2025-58752 | Vite's `server.fs` settings were not applied to HTML files | LOW | 2.3 | Sep 8, 2025 |
| CVE-2025-58751 | Vite middleware may serve files starting with the same name with the public directory | LOW | 2.3 | Sep 8, 2025 |
| CVE-2025-46565 | Vite's server.fs.deny bypassed with /. for files under project root | MEDIUM | 6.0 | May 1, 2025 |
| CVE-2025-32395 | Vite has an `server.fs.deny` bypass with an invalid `request-target` | MEDIUM | 6.0 | Apr 10, 2025 |
| CVE-2025-31486 | Vite allows server.fs.deny to be bypassed with .svg or relative paths | MEDIUM | 5.3 | Apr 3, 2025 |
| CVE-2025-31125 KEV | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query | HIGH | 7.5 | Mar 31, 2025 |
| CVE-2025-30208 | Vite bypasses server.fs.deny when using `?raw??` | HIGH | 7.5 | Mar 24, 2025 |
| CVE-2025-24010 | Vite allows any websites to send any requests to the development server and read the response | MEDIUM | 6.5 | Jan 20, 2025 |
| CVE-2024-45812 | DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vite | MEDIUM | 4.8 | Sep 17, 2024 |
| CVE-2024-45811 | server.fs.deny bypassed when using ?import&raw in vite | MEDIUM | 6.9 | Sep 17, 2024 |
| CVE-2024-31207 | Vite's `server.fs.deny` did not deny requests for patterns with directories | MEDIUM | 5.9 | Apr 4, 2024 |
| CVE-2024-23331 | Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem | HIGH | 7.5 | Jan 19, 2024 |
| CVE-2023-49293 | Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite | MEDIUM | 6.1 | Dec 4, 2023 |
| CVE-2023-34092 | Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//) | HIGH | 7.5 | Jun 1, 2023 |
| CVE-2022-35204 | Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service. | HIGH | 8.7 | Aug 18, 2022 |
Showing 1 to 22 of 22 CVEs