VendorsVitejsviteall versions
Vulnerabilities

Vitejs Vite

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-39363
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
Published 2026-04-07 · Modified
8.2EPSS 0.026
CVE-2026-39364
Vite has a `server.fs.deny` bypass with queries
Published 2026-04-07 · Modified
8.2EPSS 0.015
CVE-2026-53571
Vite: `server.fs.deny` bypass on Windows alternate paths
Published 2026-06-22 · Analyzed
8.2EPSS 0.006
CVE-2025-30208
Vite bypasses server.fs.deny when using `?raw??`
Published 2025-03-24 · Analyzed
7.51 PoCEPSS 0.748
CVE-2025-31125
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Published 2025-03-31 · Analyzed
7.5KEVEPSS 0.647
CVE-2023-34092
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
Published 2023-06-01 · Modified
7.5EPSS 0.031
CVE-2024-23331
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
Published 2024-01-19 · Modified
7.5EPSS 0.008
CVE-2025-24010
Vite allows any websites to send any requests to the development server and read the response
Published 2025-01-20 · Analyzed
6.5EPSS 0.003
CVE-2026-39365
Vite has a Path Traversal in Optimized Deps `.map` Handling
Published 2026-04-07 · Analyzed
6.3EPSS 0.010
CVE-2023-49293
Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite
Published 2023-12-04 · Modified
6.1EPSS 0.010
CVE-2025-46565
Vite's server.fs.deny bypassed with /. for files under project root
Published 2025-05-01 · Analyzed
6.0EPSS 0.012
CVE-2025-58751
Vite middleware may serve files starting with the same name with the public directory
Published 2025-09-08 · Analyzed
5.3EPSS 0.012
CVE-2025-58752
Vite's `server.fs` settings were not applied to HTML files
Published 2025-09-08 · Analyzed
5.3EPSS 0.006
CVE-2022-35204
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
Published 2022-08-18 · Modified
4.3EPSS 0.013