Catalog / Vite

Vite security advisories

All 19 advisories Vite has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
1919 carry a CVE
high
5
medium
12
low
2
Fix in the archive
4of 19 matched to a release
Oldest
1 Jun 20233.2 years ago

15 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2025-62522medium

`server.fs.deny` bypassed with `\` on Windows

GHSA-93m4-6634-74q7Fixed in 7.1.11, not held here
CVE-2025-58752low

`server.fs` settings was not applied to HTML files

GHSA-jqfw-vq24-v9c3Fixed in 7.1.5, not held here
CVE-2025-58751low

Files starting with the same name with the public directory were served

GHSA-g4jq-h2w9-997cFixed in 7.1.5, not held here
CVE-2025-46565medium

`server.fs.deny` bypassed with `/.` for files under project `root`

GHSA-859w-5945-r5v3Fixed in 6.3.4, not held here
CVE-2025-32395medium

`server.fs.deny` bypassed with an invalid `request-target`

GHSA-356w-63v5-8wf4Fixed in 6.2.6, not held here
CVE-2025-31486medium

`server.fs.deny` bypassed with `.svg` or relative paths

GHSA-xcj6-pq6g-qj4xFixed in 6.2.5, not held here
CVE-2025-31125medium

`server.fs.deny` bypassed for `inline` and `raw` with `?import` query

GHSA-4r4m-qw57-chr8Fixed in 6.2.4, not held here
CVE-2025-30208medium

server.fs.deny bypassed when using `?raw??`

GHSA-x574-m823-4x7wFixed in 6.2.3, not held here
CVE-2025-24010medium

Any websites were able to send any requests to the development server and read the response

GHSA-vg6x-rcgg-rjx6Fixed in 6.0.9, not held here
CVE-2024-45811medium

server.fs.deny bypassed when using ?import&raw

GHSA-9cwx-2883-4wfxFixed in 5.4.6, not held here
CVE-2024-45812medium

DOM Clobbering gadget found in vite bundled scripts that leads to XSS

GHSA-64vr-g452-qvp3Fixed in 5.4.6, not held here
CVE-2024-31207medium

`server.fs.deny` did not deny requests for patterns with directories.

GHSA-8jhw-289h-jh2gFixed in 2.9.18, not held here
CVE-2024-23331high

Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

GHSA-c24v-8rfc-w8vwFixed in 2.9.17, not held here
CVE-2023-49293medium

XSS vulnerability in `server.transformIndexHtml` via URL payload

GHSA-92r3-m2mg-pj97Fixed in 4.4.12, not held here
CVE-2023-34092high

Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)

GHSA-353f-5xf4-qw67Fixed in 2.9.16, not held here