`server.fs.deny` bypass on Windows alternate paths
Vite security advisories
All 19 advisories Vite has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 1919 carry a CVE
- high
- 5
- medium
- 12
- low
- 2
- Fix in the archive
- 4of 19 matched to a release
- Oldest
- 1 Jun 20233.2 years ago
15 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productArbitrary File Read via Vite Dev Server WebSocket
`server.fs.deny` bypassed with queries
Path Traversal in Optimized Deps `.map` Handling
`server.fs.deny` bypassed with `\` on Windows
`server.fs` settings was not applied to HTML files
Files starting with the same name with the public directory were served
`server.fs.deny` bypassed with `/.` for files under project `root`
`server.fs.deny` bypassed with an invalid `request-target`
`server.fs.deny` bypassed with `.svg` or relative paths
`server.fs.deny` bypassed for `inline` and `raw` with `?import` query
server.fs.deny bypassed when using `?raw??`
Any websites were able to send any requests to the development server and read the response
server.fs.deny bypassed when using ?import&raw
DOM Clobbering gadget found in vite bundled scripts that leads to XSS
`server.fs.deny` did not deny requests for patterns with directories.
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
XSS vulnerability in `server.transformIndexHtml` via URL payload
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)