Multiple security vulnerabilities affecting vite (npm) versions.
CVE-2025-31125 (CVSS 5.3 — Medium · CVSSv4): Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting vite (npm) versions.
CVE-2025-31125 (CVSS 5.3 — Medium · CVSSv4): Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.[emaillocker id="1283"]
CVE-2024-45811 (CVSS 6.9 — High · CVSSv4): Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists.
These vulnerabilities collectively present a significant risk for developers who expose their Vite development servers to the internet.
We recommend you to update Vite to version 8.0.5 or 7.3.2.
The following reports contain further technical details:
[/emaillocker]