vitejs
- Products in analyzed data
- 4
- Catalog vulnerabilities
- 24
Severity across 23 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 23 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, vitejs recorded 2 security vulnerabilities in the last 90 days across 3 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, vite had the most security vulnerabilities in the vitejs ecosystem, with 2 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-53571Vite: `server.fs.deny` bypass on Windows alternate paths | Exploitation statusPublic exploit | FixYes | Affected productvite | Published06/22/2026 | SeverityHigh |
CVE-2026-53632NTLMv2 hash disclosure via UNC path handling on Windows | Exploitation statusPublic exploit | FixYes | Affected productlaunch-editor | Published06/22/2026 | SeverityMedium |
CVE-2024-52011launch-editor vulnerable to command injection via the crafted request on Windows | Exploitation statusNot known exploited | FixYes | Affected productlaunch-editor | Published06/01/2026 | SeverityHigh |
CVE-2026-39365Vite has a Path Traversal in Optimized Deps `.map` Handling | Exploitation statusPublic exploit | FixYes | Affected productvite | Published04/07/2026 | SeverityMedium |
CVE-2026-39364Vite has a `server.fs.deny` bypass with queries | Exploitation statusPublic exploit | FixYes | Affected productvite | Published04/07/2026 | SeverityHigh |
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | Exploitation statusPublic exploit | FixYes | Affected productvite | Published04/07/2026 | SeverityHigh |
CVE-2025-68155@vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Development | Exploitation statusPublic exploit | FixNot confirmed | Affected productvite-plugin-react | Published12/16/2025 | SeverityHigh |
CVE-2025-67489@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server | Exploitation statusPublic exploit | FixYes | Affected productvite-plugin-react | Published12/09/2025 | SeverityCritical |
CVE-2025-62522vite allows server.fs.deny bypass via backslash on Windows | Exploitation statusPublic exploit | FixYes | Affected productvite | Published10/20/2025 | SeverityMedium |
CVE-2025-58752Vite's `server.fs` settings were not applied to HTML files | Exploitation statusPublic exploit | FixNot confirmed | Affected productvite | Published09/08/2025 | SeverityLow |
CVE-2025-58751Vite middleware may serve files starting with the same name with the public directory | Exploitation statusPublic exploit | FixNot confirmed | Affected productvite | Published09/08/2025 | SeverityLow |
CVE-2025-46565Vite's server.fs.deny bypassed with /. for files under project root | Exploitation statusPublic exploit | FixYes | Affected productvite | Published05/01/2025 | SeverityMedium |
CVE-2025-32395Vite has an `server.fs.deny` bypass with an invalid `request-target` | Exploitation statusPublic exploit | FixYes | Affected productvite | Published04/10/2025 | SeverityMedium |
CVE-2025-31486Vite allows server.fs.deny to be bypassed with .svg or relative paths | Exploitation statusPublic exploit | FixYes | Affected productvite | Published04/03/2025 | SeverityMedium |
CVE-2025-31125Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query | Exploitation statusKEV | FixYes | Affected productvite | Published03/31/2025 | SeverityMedium |
CVE-2025-30208Vite bypasses server.fs.deny when using `?raw??` | Exploitation statusPublic exploit | FixNot confirmed | Affected productvite | Published03/24/2025 | SeverityMedium |
CVE-2025-24010Vite allows any websites to send any requests to the development server and read the response | Exploitation statusPublic exploit | FixYes | Affected productvite | Published01/20/2025 | SeverityMedium |
CVE-2024-45812DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vite | Exploitation statusPublic exploit | FixYes | Affected productvite | Published09/17/2024 | SeverityMedium |
CVE-2024-45811server.fs.deny bypassed when using ?import&raw in vite | Exploitation statusPublic exploit | FixYes | Affected productvite | Published09/17/2024 | SeverityMedium |
CVE-2024-31207Vite's `server.fs.deny` did not deny requests for patterns with directories | Exploitation statusNot known exploited | FixYes | Affected productvite | Published04/04/2024 | SeverityMedium |
CVE-2024-23331Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem | Exploitation statusPublic exploit | FixNot confirmed | Affected productvite | Published01/19/2024 | SeverityHigh |
CVE-2023-49293Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite | Exploitation statusNot known exploited | FixNot confirmed | Affected productvite | Published12/04/2023 | SeverityMedium |
CVE-2023-34092Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//) | Exploitation statusPublic exploit | FixYes | Affected productvite | Published06/01/2023 | SeverityHigh |
CVE-2022-35204CVE-2022-35204 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/18/2022 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan