launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Quelle: GitHub Advisory Database, stündlich abgerufen. · Zuletzt geprüft 21.09.2026
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
vite: `server.fs.deny` bypass on Windows alternate paths
launch-editor vulnerable to command injection via the crafted request on Windows
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Vite: `server.fs.deny` bypassed with queries
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
vite allows server.fs.deny bypass via backslash on Windows
Vite middleware may serve files starting with the same name with the public directory
Vite's `server.fs` settings were not applied to HTML files
Vite's server.fs.deny bypassed with /. for files under project root
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Vite bypasses server.fs.deny when using ?raw??
Websites were able to send any requests to the development server and read the response in vite
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
Vite's `server.fs.deny` is bypassed when using `?import&raw`
Vite's `server.fs.deny` did not deny requests for patterns with directories.
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service