Threat Advisory

Vite Development Server Flaw Steals Cloud Credentials and Config Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting vite (npm) versions.

CVE-2025-31125 (CVSS 5.3 — Medium · CVSSv4): Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting vite (npm) versions.

CVE-2025-31125 (CVSS 5.3 — Medium · CVSSv4): Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.[emaillocker id="1283"]

CVE-2024-45811 (CVSS 6.9 — High · CVSSv4): Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists.

These vulnerabilities collectively present a significant risk for developers who expose their Vite development servers to the internet.

RECOMMENDATION:

We recommend you to update Vite to version 8.0.5 or 7.3.2.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu