CVE-2025-30208

Medium5.3Published on March 24, 2025

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

Early warning: exploitation observed

  • Exploitation observed since Apr 28, 2025
  • Not yet in the official CISA catalogue
  • First attack observed 34 days after disclosure
  • Confirmed by sensors, not only by reports

Source: VulnCheck KEV · Sep 15, 2026 Sep 14, 2026 Sep 13, 2026 Sep 12, 2026 Sep 11, 2026 Sep 10, 2026

CVSS score5.3 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness type (CWE)CWE-200, CWE-284
Vendorsvitejs

Affected products

VendorsProductVersions
vitejsvite< 4.5.10

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database