Skip to content
Noroxi

vitejs records

16 published records for vendor vitejs.

Researcher profile

Entered KEV
1 · 6.3%
Weaponized
1 · 6.3%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
297 days

All records

16 records
  • CVE-2025-31125
    79This week

    Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

    HighCVSS 7.5KEVWeaponizedEPSS 65%

    vitejs · viteMar 31, 2025

  • Vite bypasses server.fs.deny when using `?raw??`

    HighCVSS 7.5Proof of conceptEPSS 75%

    vitejs · viteMar 24, 2025

  • Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket

    HighCVSS 8.2Proof of conceptEPSS 3%

    vitejs · viteApr 7, 2026

  • Vite has a `server.fs.deny` bypass with queries

    HighCVSS 8.2Proof of conceptEPSS 2%

    vitejs · viteApr 7, 2026

  • Vite: `server.fs.deny` bypass on Windows alternate paths

    HighCVSS 8.2Proof of conceptEPSS 1%

    vitejs · viteJun 22, 2026

  • Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)

    HighCVSS 7.5Proof of conceptEPSS 3%

    vitejs · viteJun 1, 2023

  • Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

    HighCVSS 7.5No exploitEPSS 1%

    vitejs · viteJan 19, 2024

  • Vite allows any websites to send any requests to the development server and read the response

    MediumCVSS 6.5No exploitEPSS 0%

    vitejs · viteJan 20, 2025

  • Vite has a Path Traversal in Optimized Deps `.map` Handling

    MediumCVSS 6.3Proof of conceptEPSS 1%

    vitejs · viteApr 7, 2026

  • DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vite

    MediumCVSS 6.4No exploitEPSS 1%

    vitejs · viteSep 17, 2024

  • Vite's server.fs.deny bypassed with /. for files under project root

    MediumCVSS 6.0Proof of conceptEPSS 1%

    vitejs · viteMay 1, 2025

  • Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite

    MediumCVSS 6.1Proof of conceptEPSS 1%

    vitejs · viteDec 4, 2023

  • server.fs.deny bypassed when using ?import&raw in vite

    MediumCVSS 4.8No exploitEPSS 1%

    vitejs · viteSep 17, 2024

  • Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.

    MediumCVSS 4.3No exploitEPSS 1%

    vitejs · viteAug 18, 2022

  • Vite middleware may serve files starting with the same name with the public directory

    LowCVSS 2.3Proof of conceptEPSS 1%

    vitejs · viteSep 8, 2025

  • Vite's `server.fs` settings were not applied to HTML files

    LowCVSS 2.3No exploitEPSS 1%

    vitejs · viteSep 8, 2025