CVE-2025-30208Active Exploitation(vitejs / vite)

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch vitejs vite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vite

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 18 mentions across 11 observed days

What's happening

  • Active exploitation reported across 8 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • General: 4 classified signals
  • Peaked 7d ago at 5 mentions (2026-04-02); latest day: 1
  • 18 total mentions across 11 days

Affected systems

Vendors
Products
vite

Deep dive

Activity timeline18 mentions / 11d
01345Mentions · 2026-01-28: 1Mentions · 2026-02-05: 1Mentions · 2026-02-07: 1Mentions · 2026-04-02: 5Mentions · 2026-04-03: 2Mentions · 2026-04-04: 1Mentions · 2026-04-07: 2Mentions · 2026-08-30: 2Mentions · 2026-09-14: 1Mentions · 2026-09-15: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-04-02: 1Exploit Tool / Code · 2026-04-02: 1Active Exploitation · 2026-04-02: 4Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-08-30: 1Active Exploitation · 2026-09-14: 1Active Exploitation · 2026-09-15: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-04-02: 2Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-09-14: 1Technical Details · 2026-02-07: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-07: 2Technical Details · 2026-08-30: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-15: 101-2802-0502-0704-0204-0304-0404-0708-3009-1409-1509-16
Signal classification5 categories
Active Exploitation
844.4%
General
422.2%
Patch
316.7%
Disclosure
211.1%
PoC
15.6%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-01-281
PoC1
2026-02-051
Patch1
2026-02-071
Patch1
2026-04-025
Active Exploitation4General1
2026-04-032
Active Exploitation1General1
2026-04-041
General1
2026-04-072
Disclosure2
2026-08-302
Active Exploitation1Patch1
2026-09-141
Active Exploitation1
2026-09-151
Active Exploitation1
2026-09-161
General1
Full discourse18 posts
  • 0x0smilex@0x0smilex
    Patch

    CVE-2025-30208 (ViteJS Arbitrary File Read) + Leaked JWT Secrets = Full Admin Takeover ⚡️.Used Vitejs path traversal to exfiltrate .env & .tmp/data.db then generated forged tokens -> Unauthenticated access to /admin. Patch Now 🚨 #BugBounty #EthicalHacking #bugbountytips https://t.co/DD1ETzPi3A

    Post summary

    The tweet highlights a path traversal flaw in ViteJS that allows reading sensitive files and forging JWTs for admin takeover, and urges users to apply the patch.

    251033518016.9K
    2.2K followersView on X
  • SANS.edu Internet Storm Center@sans_isc
    Active Exploitation

    Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208) https://isc.sans.edu/diary/32860 https://t.co/qmQHohDqz0

    Post summary

    The SANS diary link reports ongoing exploitation attempts against exposed Vite installations for CVE-2025-30208, but provides no PoC, technical details, or patch guidance.

    030601.2K
    117.3K followersView on X
  • madco@Mobilpadde
    PoC

    Huge thanks to @0m3rexe for responsibly disclosing a vulnerability related to CVE-2025-30208 in my setup at https://hasty.dev 🛡️ He provided a clear proof-of-concept and verified the patch quickly. If you need a professional security researcher, check him out! #infosec 🫡

    Post summary

    The user thanks a researcher for a proof‑of‑concept and patch verification of CVE‑2025‑30208, but provides no technical details or evidence of active exploitation.

    11030109
    418 followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    A mass-scanning operation is exploiting exposed Vite development servers to retrieve cloud credentials, configuration data, and other secrets from AWS and Azure environments. - Attackers exploit CVE-2026-39364 by manipulating query parameters to bypass file-access restrictions and return protected files in plaintext. - Scanning targets environment files, AWS and Azure credentials, Terraform state, serverless configurations, process environment data, and system files, with traversal and encoding variants used to evade filtering. - F5 observed more than 800 attacks and approximately 32,000 events over one month; activity originated mainly from the United States, Belgium, and the Netherlands and used Google Cloud IP ranges. - Related activity also exploited CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811. Exposed servers should be patched and reachable secrets rotated.

    Post summary

    The text reports active in-the-wild exploitation of CVE-2026-39364 via manipulation of Vite development servers to access sensitive files, with observed mass-scanning activity and multiple related CVEs also referenced. Remediation guidance includes patching servers and rotating exposed secrets.

    0002081
    103 followersView on X
  • NY-squared AI@NYsquaredAI
    Disclosure

    Exactly right. In CVE-2025-30208, a custom str subclass bypassed the entire sandbox. Input validation alone isn't enough. You need 3 layers at runtime: → Syscall monitoring → Policy-based allowlists → Anomaly detection Are you seeing any teams actually running runtime policy audits in production agent workloads?

    Post summary

    The tweet discloses details of CVE‑2025‑30208, noting that a custom Python str subclass can bypass the sandbox and emphasizing the necessity of syscall monitoring, policy allowlists, and anomaly detection, yet it offers no PoC, exploit code, patch, or evidence of active exploitation.

    10010187
    29 followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    Automated scanning in August 2026 increasingly exploited exposed Vite development servers to steal cloud credentials and deployment data. - Attackers abused CVE-2026-39364, an unauthenticated access-control bypass affecting specified Vite versions, by manipulating query parameters on the internal @ fs route. - Scanners also tested CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811 using extensive wordlists targeting environment files, AWS and Azure credential stores, Terraform state, serverless artifacts, and Linux process data. - Honeypot telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events; exposed files could enable cloud account takeover, lateral movement, or broader infrastructure compromise. VULNERABILITY CVE-2024-45811 CVE-2025-30208 CVE-2025-31125 CVE-2026-39364

    Post summary

    The text reports active, ongoing exploitation of multiple Vite-related CVEs (notably CVE-2026-39364) in August 2026, with automated scanners targeting exposed development servers to steal cloud credentials. Honeypot telemetry captured 807 attack sessions and ~32,000 events, confirming real-world exploitation.

    0001044
    74 followersView on X
  • arLevi@ar_levi
    General

    @NicHulscher playd with AI on my computer, later I see an attack on my server in production for the same urls it knew was written even though i never pushed code to prod. AI develop SAME code for everyone, then attack the holes it knows exists! cve-2025-30208 All we need is a good cyberattack

    Post summary

    The tweet mentions CVE-2025-30208 in a vague, opinion-based context about AI-generated code security risks, without providing specific technical details, PoC, exploit tools, patches, or confirmed exploitation claims.

    00000270
    67 followersView on X
  • zerizeri(インフラエンジニア技術ブログ)@zerizerizeri_bl
    Patch

    CVE-2025-30208(Vite dev serverの任意ファイル読み取り)を狙う /@fs/...?...raw?? 形式のスキャンが増えている可能性。Viteを外部公開していないか確認し、修正版へ更新を。 #セキュリティ #注意喚起 #脆弱性 $CVE

    Post summary

    The tweet alerts users to CVE-2025-30208, an arbitrary file read in Vite dev server, and urges checking for external exposure and applying the patched version.

    00000125
    48 followersView on X
  • zerizeri(インフラエンジニア技術ブログ)@zerizerizeri_bl
    Active Exploitation

    【WAFログ速報】 35.221.195.36(22回): 意図しないファイルの公開の可能性(~)攻撃を検知。/@fs/home/ubuntu/.ovh.conf?raw??に対して不正なリクエストを22回送信。システムの脆弱性を探る試行が確認。(CVE-2025-30208?) #WAF #セキュリティ #脅威検知 https://t.co/Jm2ZqRwjLV

    Post summary

    The WAF logs indicate 22 malicious attempts targeting an unintended file exposure endpoint, implying active exploitation attempts possibly linked to CVE-2025-30208, without further detail, PoC, or patch information.

    0000049
    48 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 (Vite Dev Server), Arbitrary File Read, #CVE-2025-30208 (Medium) https://dailycve.com/vite-dev-server-arbitrary-file-read-cve-2025-30208-medium/

    Post summary

    The text announces an arbitrary file read vulnerability (CVE‑2025‑30208) in Vite Dev Server, rating it as medium severity.

    0000067
    178 followersView on X
  • Hawley@Hawley
    General

    Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), (Thu, Apr 2nd) (SANS Internet Storm Center) 🛡️ http://TrustyPotato.com https://t.co/iJYFQRsZeF

    Post summary

    The brief tweet notes reported attempts to exploit CVE-2025-30208 but provides no technical, PoC, or patch details.

    00000343
    1.2K followersView on X
  • CompuChris@compuchris
    General

    Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), (Thu, Apr 2nd) #CISO https://isc.sans.edu/diary/rss/32860

    Post summary

    The tweet notes that attackers are attempting to target exposed Vite installations via CVE-2025-30208, but it provides no further technical or remedial details.

    00000198
    1.7K followersView on X
  • Jedi Security •|• OSS@JedisecX
    Active Exploitation

    Attempts to Exploit Exposed “Vite” Installs (CVE-2025-30208) https://ift.tt/OU285xs

    Post summary

    The message reports ongoing attempts to exploit CVE‑2025‑30208 against exposed Vite installations, indicating real‑world exploitation activity, but no PoC, exploit code, patch, or detailed technical description is provided.

    00000159
    582 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Active Exploitation

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), (Thu, Apr 2nd) Intel Report: https://ift.tt/6absjXA

    Post summary

    The alert reports real‑world attempts to exploit CVE‑2025‑30208 in exposed Vite installations, indicating active exploitation activity, but it does not provide PoC, exploit code, or patch information.

    00000152
    281 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    🚨 Threat Alert: Vite Arbitrary File Read Attempts (CVE-2025-30208) 📅 Date: 2026-04-02 📆 Timeline: 2025-04-15 — Vendor advisories / CVE disclosures (Broadcom/Symantec noted the issue and patched versions). 2025-07-31 — Public technical write-ups (OffSec) and detailed PoC discussion published. 2025–2026 — Multiple public PoCs/scanners appeared on GitHub (automated scanning tools targeting CVE-2025-30208). 2026-04-02 — Honeypots observed active scanning and file-read attempts (this report). 📍 Location: Internet-exposed hosts (no specific geographic region identified) 📌 Attribution: Unknown — likely opportunistic internet scanners and automated PoC/tool users. 📝 Summary: Honeypots observed opportunistic scanning and exploitation attempts against internet‑exposed Vite development servers using the CVE‑2025‑30208 @fs path‑handling bypass (requests use "/@fs/" with "?raw??"-style suffixes to force raw file returns). Vulnerability and exploit technique are confirmed by public vendor notices and write‑ups; public PoC/scanner code is available on GitHub. ⚔️ Attack Details: - Attack Type: Arbitrary file read / information disclosure via exploitation of public-facing application (CVE-2025-30208) - Target: Internet-exposed Vite development servers (vite dev server processes, commonly on port 5173; attackers observed using standard HTTP/HTTPS ports as well) 📈 Impact: Confidentiality loss: arbitrary local-file disclosure (examples observed: /etc/environment, /home/app/.aws/credentials). Exposure of credentials and configuration can enable credential theft, cloud account takeover, lateral movement and data exfiltration. No service-disruption observed in the reported activity; overall severity to affected deployments: high for confidentiality. 🔗 Related Resources: - https://isc.sans.edu/diary/Attempts+to+Exploit+Exposed+Vite+Installs+CVE202530208/32860/ - https://isc.sans.edu/diary/rss/32860 - https://isc.sans.edu/diary/32860 - https://www.offsec.com/blog/cve-2025-30208/ - https://github.com/vitejs/vite - https://github.com/ThemeHackers/CVE-2025-30208 - https://www.broadcom.com/support/security-center/protection-bulletin/cve-2025-30208-vite-arbitrary-file-read-vulnerability 🛡️ Recommended Actions: - Do NOT expose Vite dev servers to the internet; bind dev server to localhost or use SSH/VPN to access remotely. - Upgrade Vite to patched versions (e.g., Vite ≥ 6.2.3 and other patched releases per vendor advisories). - Place dev servers behind a firewall/reverse proxy and require authentication; restrict ports to internal networks. - Add WAF/IDS rules to detect/block requests to /@fs/* and parameters containing ?raw?? or ?import&raw. - Monitor logs for accesses to /@fs/, ?raw??, and unusual file-read responses; alert on reads of sensitive files (/etc/, ~/.aws/, .env). - If credentials were exposed, rotate keys/secrets immediately and review cloud access logs for abuse. - Apply least-privilege to service accounts and avoid storing long-lived credentials on developer hosts. - For detection, add SIEM rules looking for ES-module‑wrapped file contents ("export default") returned from dev servers. 🫨 Attack Vectors: - T1190 - Exploit Public-Facing Application (Vite dev server @fs path bypass) - T1005 - Data from Local System (arbitrary file read / local file disclosure) - T1552 - Credentials in Files (harvesting files such as ~/.aws/credentials) - T1595 - Active Scanning (network scanning for exposed Vite instances) - T1082 - System Information Discovery (enumeration via disclosed files) 🏷 Tags: #vite #CVE-2025-30208 #arbitrary file read #information disclosure #web #development servers #honeypot #credentials #Cybersecurity

    Post summary

    The report confirms CVE‑2025‑30208 is actively exploited on the internet, with public PoCs and active scanning observed. Patch updates and strict access controls are recommended to mitigate the high confidentiality risk.

    00000148
    277 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    🚨 Threat Alert: Attempts to Exploit Exposed Vite Installs (CVE-2025-30208) 📅 Date: 2026-04-02 📆 Timeline: 2025-07-31: Public advisories describing CVE-2025-30208 and technical bypass published (OffSec advisory). 2026-04-02: Honeypots recorded scanning and exploitation attempts against internet-exposed Vite dev servers (probe URLs attempting /@fs/ path traversal and ?raw?? suffix). Post-2026-04: Ongoing opportunistic scanning expected unless servers are patched/blocked. 📍 Location: Internet-exposed hosts (no specific geographic region identified) 📌 Attribution: Unknown — consistent with opportunistic internet scanning and commodity scanners/botnets (no credible public attribution) 📝 Summary: Honeypots observed scanning and exploitation attempts against internet‑exposed Vite development servers that abuse Vite’s /@fs/ URL handling to read arbitrary files. Attackers append a crafted query suffix (observed patterns include "?raw??" and the documented bypass "?import&raw??") which confuses Vite’s import parser and returns file contents wrapped as an ES module. Probe URLs included "/@fs/../../../../../etc/environment?raw??", "/@fs/etc/environment?raw??" and "/@fs/home/app/.aws/credentials?raw??". The behavior matches CVE-2025-30208. Exploitation requires the Vite dev server to be remotely accessible (commonly listens on port 5173). ⚔️ Attack Details: - Attack Type: Arbitrary file read / path traversal via Vite @fs URL handling (CVE-2025-30208) - Target: Internet-exposed Vite development servers and developer workstations/build tooling (Vite dev server, typically port 5173) 📈 Impact: Disclosure and exfiltration of sensitive files (e.g., /etc/environment, .aws/credentials), credential theft, unauthorized access to cloud resources and internal systems, increased risk of lateral movement and data loss. Financial/operational impact depends on exposed credentials and environment — no confirmed monetary loss reported. 🔗 Related Resources: - https://www.offsec.com/blog/cve-2025-30208/ - https://isc.sans.edu/diary/Attempts+to+Exploit+Exposed+Vite+Installs+CVE202530208/32860/ - https://github.com/vitejs/vite - https://isc.sans.edu/diary/rss/32860 🛡️ Recommended Actions: - Patch: Upgrade Vite to a version that fixes CVE-2025-30208. - Network controls: Ensure Vite dev servers are not bound to public interfaces — bind to localhost or use firewall rules to block external access (block port 5173 on public-facing interfaces). - Access controls: Place dev servers behind authenticated reverse proxies or VPNs; use IP allowlists. - Secrets hygiene: Remove credentials from local files where possible; rotate any potentially exposed credentials (AWS keys, tokens) and enforce least privilege. - Detection: Monitor web/access logs and WAF/IDS for requests containing "/@fs/" and query patterns containing "??" or "import&raw"; create signatures to detect and block these probes. - Hardening: Disable serving arbitrary filesystem paths in dev tooling; run dev servers in isolated environments/containers. - Incident response: If compromise suspected, perform credential scanning, secret exposure assessment, credential rotation, and forensic analysis of affected hosts. 🫨 Attack Vectors: - CVE-2025-30208 — Vite @fs path traversal bypass via crafted query suffix (?import&raw?? / ?raw??) - T1190 - Exploit Public-Facing Application (exposed Vite dev server reachable from the internet) - T1595 - Active Scanning (internet-wide scanning for exposed Vite instances) - T1083 - File and Directory Discovery (enumeration and reading of filesystem paths) - T1552.001 - Unsecured Credentials: Credentials in Files (e.g., .aws/credentials) - T1005 - Data from Local System (exfiltration of file contents) 🏷 Tags: #vite #CVE-2025-30208 #arbitrary-file-read #path-traversal #dev-server #exposed-services #credential-theft #Cybersecurity

    Post summary

    The alert confirms active exploitation attempts against publicly exposed Vite development servers using CVE-2025-30208, with specific probe patterns detailed and recommended patching and firewall mitigations.

    00000126
    277 followersView on X
  • Shah Sheikh@shah_sheikh
    General

    [SANS Internet Storm Center] Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), (Thu, Apr 2nd). From its GitHub repo: "Vite (French word for "quick", pronounced /vi?t/, like "veet") is a new breed of frontend build tooling that... http://ow.ly/Zaju106wIOK

    Post summary

    SANS Internet Storm Center alerts on attempts to exploit CVE-2025-30208 in Vite, but provides no PoC, exploit code, patch, or detailed vulnerability information.

    00000157
    2.2K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-mod_security_crs Module Update 4.23.0-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: mod_security_crs 4.23.0-1 This update includes support for vulnerability(CVE-2025-30208). The module update can be... https://kusanagi.tokyo/en/releases/22972/

    Post summary

    KUSANAGI 9 releases an update to the mod_security_crs module, indicating that it now includes support for CVE-2025-30208, effectively providing a patch or mitigation for the vulnerability.

    0000064
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvitejsvite-node.js-

Explore more