CVE-2025-30208
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.
Early warning: exploitation observed
- Exploitation observed since Apr 28, 2025
- Not yet in the official CISA catalogue
- First attack observed 34 days after disclosure
- Confirmed by sensors, not only by reports
Source: VulnCheck KEV · Sep 15, 2026 Sep 14, 2026 Sep 13, 2026 Sep 12, 2026 Sep 11, 2026 Sep 10, 2026
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:NAffected products
| Vendors | Product | Versions |
|---|---|---|
| vitejs | vite | < 4.5.10 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
