Security changelog

Vite

22 fixes · 7 high/critical

Source: GitHub Advisory Database, pulled hourly. · Last checked Sep 21, 2026

mediumGHSA-v6wh-96g9-6wx3CVE-2026-53632
Jun 2026

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

Affected: >= 8.0.0, <= 8.0.15 · >= 7.0.0, <= 7.3.4 · <= 6.4.2Fixed in 8.0.16, 7.3.5, 6.4.3
highGHSA-fx2h-pf6j-xcffCVE-2026-53571
Jun 2026

vite: `server.fs.deny` bypass on Windows alternate paths

Affected: >= 8.0.0, <= 8.0.15 · >= 7.0.0, <= 7.3.4 · <= 6.4.2Fixed in 8.0.16, 7.3.5, 6.4.3
highGHSA-c27g-q93r-2cwfCVE-2024-52011
Jun 2026

launch-editor vulnerable to command injection via the crafted request on Windows

Affected: <= 5.4.8Fixed in 5.4.9
mediumGHSA-4w7w-66w2-5vf9CVE-2026-39365
Apr 2026

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

Affected: >= 8.0.0, <= 8.0.4 · >= 7.0.0, <= 7.3.1 · <= 6.4.1Fixed in 8.0.5, 7.3.2, 6.4.2
highGHSA-v2wj-q39q-566rCVE-2026-39364
Apr 2026

Vite: `server.fs.deny` bypassed with queries

Affected: >= 8.0.0, <= 8.0.4 · >= 7.1.0, <= 7.3.1Fixed in 8.0.5, 7.3.2
highGHSA-p9ff-h696-f583CVE-2026-39363
Apr 2026

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

Affected: >= 8.0.0, <= 8.0.4 · >= 7.0.0, <= 7.3.1 · >= 6.0.0, <= 6.4.1Fixed in 8.0.5, 7.3.2, 6.4.2
mediumGHSA-93m4-6634-74q7CVE-2025-62522
Oct 2025

vite allows server.fs.deny bypass via backslash on Windows

Affected: >= 7.1.0, <= 7.1.10 · >= 7.0.0, <= 7.0.7 · >= 6.0.0, <= 6.4.0 · >= 2.9.18, < 3.0.0 · >= 3.2.9, < 4.0.0 · >= 4.5.3, < 5.0.0 · >= 5.2.6, <= 5.4.20Fixed in 7.1.11, 7.0.8, 6.4.1, 5.4.21
lowGHSA-g4jq-h2w9-997cCVE-2025-58751
Sep 2025

Vite middleware may serve files starting with the same name with the public directory

Affected: >= 7.1.0, <= 7.1.4 · >= 7.0.0, <= 7.0.6 · >= 6.0.0, <= 6.3.5 · <= 5.4.19Fixed in 7.1.5, 7.0.7, 6.3.6, 5.4.20
lowGHSA-jqfw-vq24-v9c3CVE-2025-58752
Sep 2025

Vite's `server.fs` settings were not applied to HTML files

Affected: >= 7.1.0, <= 7.1.4 · >= 7.0.0, <= 7.0.6 · >= 6.0.0, <= 6.3.5 · <= 5.4.19Fixed in 7.1.5, 7.0.7, 6.3.6, 5.4.20
mediumGHSA-859w-5945-r5v3CVE-2025-46565
Apr 2025

Vite's server.fs.deny bypassed with /. for files under project root

Affected: >= 6.3.0, <= 6.3.3 · >= 6.2.0, <= 6.2.6 · >= 6.0.0, <= 6.1.5 · >= 5.0.0, <= 5.4.18 · <= 4.5.13Fixed in 6.3.4, 6.2.7, 6.1.6, 5.4.19, 4.5.14
Show all 12
mediumGHSA-356w-63v5-8wf4CVE-2025-32395
Apr 2025

Vite has an `server.fs.deny` bypass with an invalid `request-target`

Affected: >= 6.2.0, < 6.2.6 · >= 6.1.0, < 6.1.5 · >= 6.0.0, < 6.0.15 · >= 5.0.0, < 5.4.18 · < 4.5.13Fixed in 6.2.6, 6.1.5, 6.0.15, 5.4.18, 4.5.13
mediumGHSA-xcj6-pq6g-qj4xCVE-2025-31486
Apr 2025

Vite allows server.fs.deny to be bypassed with .svg or relative paths

Affected: >= 6.2.0, < 6.2.5 · >= 6.1.0, < 6.1.4 · >= 6.0.0, < 6.0.14 · >= 5.0.0, < 5.4.17 · < 4.5.12Fixed in 6.2.5, 6.1.4, 6.0.14, 5.4.17, 4.5.12
mediumGHSA-4r4m-qw57-chr8CVE-2025-31125
Mar 2025

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

Affected: >= 6.2.0, < 6.2.4 · >= 6.1.0, < 6.1.3 · >= 6.0.0, < 6.0.13 · >= 5.0.0, < 5.4.16 · < 4.5.11Fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, 4.5.11
mediumGHSA-x574-m823-4x7wCVE-2025-30208
Mar 2025

Vite bypasses server.fs.deny when using ?raw??

Affected: >= 6.2.0, < 6.2.3 · >= 6.1.0, < 6.1.2 · >= 6.0.0, < 6.0.12 · >= 5.0.0, < 5.4.15 · < 4.5.10Fixed in 6.2.3, 6.1.2, 6.0.12, 5.4.15, 4.5.10
mediumGHSA-vg6x-rcgg-rjx6CVE-2025-24010
Jan 2025

Websites were able to send any requests to the development server and read the response in vite

Affected: >= 6.0.0, <= 6.0.8 · >= 5.0.0, <= 5.4.11 · <= 4.5.5Fixed in 6.0.9, 5.4.12, 4.5.6
mediumGHSA-64vr-g452-qvp3CVE-2024-45812
Sep 2024

Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS

Affected: >= 4.0.0, < 4.5.4 · >= 5.4.0, < 5.4.6 · >= 5.3.0, < 5.3.6 · >= 5.2.0, < 5.2.14 · < 3.2.11 · >= 5.0.0, < 5.1.8Fixed in 4.5.4, 5.4.6, 5.3.6, 5.2.14, 3.2.11, 5.1.8
mediumGHSA-9cwx-2883-4wfxCVE-2024-45811
Sep 2024

Vite's `server.fs.deny` is bypassed when using `?import&raw`

Affected: >= 5.4.0, <= 5.4.5 · >= 5.3.0, <= 5.3.5 · >= 4.0.0, <= 4.5.3 · <= 3.2.10 · >= 5.2.0, < 5.2.14 · >= 5.0.0, <= 5.1.7Fixed in 5.4.6, 5.3.6, 4.5.4, 3.2.11, 5.2.14, 5.1.8
mediumGHSA-8jhw-289h-jh2gCVE-2024-31207
Apr 2024

Vite's `server.fs.deny` did not deny requests for patterns with directories.

Affected: >= 2.7.0, <= 2.9.17 · >= 3.0.0, <= 3.2.8 · >= 4.0.0, <= 4.5.2 · >= 5.0.0, <= 5.0.12 · >= 5.1.0, <= 5.1.6 · >= 5.2.0, <= 5.2.5Fixed in 2.9.18, 3.2.10, 4.5.3, 5.0.13, 5.1.7, 5.2.6
highGHSA-c24v-8rfc-w8vwCVE-2024-23331
Jan 2024

Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

Affected: >= 2.7.0, <= 2.9.16 · >= 3.0.0, <= 3.2.7 · >= 4.0.0, <= 4.5.1 · >= 5.0.0, <= 5.0.11Fixed in 2.9.17, 3.2.8, 4.5.2, 5.0.12
mediumGHSA-92r3-m2mg-pj97CVE-2023-49293
Dec 2023

Vite XSS vulnerability in `server.transformIndexHtml` via URL payload

Affected: >= 4.4.0, < 4.4.12 · = 4.5.0 · >= 5.0.0, < 5.0.5Fixed in 4.4.12, 4.5.1, 5.0.5
highGHSA-353f-5xf4-qw67CVE-2023-34092
Jun 2023

Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)

Affected: < 2.9.16 · >= 3.0.2, < 3.2.7 · >= 4.0.0, < 4.0.5 · >= 4.1.0, < 4.1.5 · >= 4.2.0, < 4.2.3 · >= 4.3.0, < 4.3.9Fixed in 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, 4.3.9
highGHSA-mv48-hcvh-8jj8CVE-2022-35204
Aug 2022

Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service

Affected: < 2.9.13 · >= 3.0.0-alpha.0, < 3.0.0-beta.4Fixed in 2.9.13, 3.0.0-beta.4