Exposure of Vite

Miscellaneous
63
exposure score
64,692
sites use
1
exploited
0
critical
Vexday analysis

Com 21 CVEs catalogadas e 6 surgidas nos últimos 90 dias, o Vite apresenta ritmo recente de descoberta de vulnerabilidades que merece acompanhamento contínuo. A taxa de exploração ativa — 4,76% das CVEs presentes no catálogo KEV da CISA — está 10,6 vezes acima da média geral do catálogo, indicando que falhas nessa tecnologia têm atraído atenção de agentes maliciosos de forma desproporcional ao seu volume total. O tipo de falha mais comum é CWE-200 (exposição de informações sensíveis), padrão que, em ferramentas de build e desenvolvimento, pode facilitar vazamento de dados de configuração ou código-fonte em ambientes mal isolados. A CVE mais perigosa em exploração ativa no momento é CVE-2025-31125, com EPSS de 0,621 — probabilidade elevada de exploração —, sendo prioritária para equipes que ainda não aplicaram a correção correspondente.

CVEs

21 results
CVE-2025-31125MEDIUMVite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryEPSS 58.8%KEVCVE-2025-30208MEDIUMVite bypasses server.fs.deny when using `?raw??`EPSS 75.0%CVE-2025-31486MEDIUMVite allows server.fs.deny to be bypassed with .svg or relative pathsEPSS 38.7%CVE-2026-39363HIGHVite Affected by Arbitrary File Read via Vite Dev Server WebSocketEPSS 3.3%CVE-2023-34092HIGHVite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)EPSS 3.2%CVE-2026-39364HIGHVite has a `server.fs.deny` bypass with queriesEPSS 2.1%CVE-2025-32395MEDIUMVite has an `server.fs.deny` bypass with an invalid `request-target`EPSS 1.7%CVE-2025-58751LOWVite middleware may serve files starting with the same name with the public directoryEPSS 1.2%CVE-2025-46565MEDIUMVite's server.fs.deny bypassed with /. for files under project rootEPSS 1.2%CVE-2024-45811MEDIUMserver.fs.deny bypassed when using ?import&raw in viteEPSS 1.0%CVE-2025-62522MEDIUMvite allows server.fs.deny bypass via backslash on WindowsEPSS 1.0%CVE-2023-49293MEDIUMCross-site Scripting in `server.transformIndexHtml` via URL payload in viteEPSS 1.0%CVE-2026-39365MEDIUMVite has a Path Traversal in Optimized Deps `.map` HandlingEPSS 0.9%CVE-2024-23331HIGHVite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystemEPSS 0.8%CVE-2024-31207MEDIUMVite's `server.fs.deny` did not deny requests for patterns with directoriesEPSS 0.7%CVE-2024-45812MEDIUMDOM Clobbering gadget found in vite bundled scripts that leads to XSS in ViteEPSS 0.6%CVE-2026-53571HIGHVite: `server.fs.deny` bypass on Windows alternate pathsEPSS 0.6%CVE-2025-58752LOWVite's `server.fs` settings were not applied to HTML filesEPSS 0.6%CVE-2024-52011HIGHlaunch-editor vulnerable to command injection via the crafted request on WindowsEPSS 0.5%CVE-2026-53632MEDIUMNTLMv2 hash disclosure via UNC path handling on WindowsEPSS 0.3%