CVE-2025-31125Active Exploitation(vitejs / vite)

HIGHCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch vitejs vite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-200CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vite

Threat summary

  • Active exploitation appears in 7 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Peaked 5d ago at 2 mentions (2026-01-28); latest day: 2
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
vite

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-01-28: 2Mentions · 2026-02-06: 1Mentions · 2026-02-25: 1Mentions · 2026-04-08: 1Mentions · 2026-09-14: 1Mentions · 2026-09-15: 2Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-28: 2Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-09-14: 1Active Exploitation · 2026-09-15: 2Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-25: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-15: 201-2802-0602-2504-0809-1409-15
Signal classification2 categories
Active Exploitation
787.5%
Patch
112.5%
Referenced assets28 URLs
Classification over time
DateTotalLabels
2026-01-282
Active Exploitation2
2026-02-061
Patch1
2026-02-251
Active Exploitation1
2026-04-081
Active Exploitation1
2026-09-141
Active Exploitation1
2026-09-152
Active Exploitation2
Full discourse8 posts
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    Team Cymru reports the 25 CVEs with the most observed exploitation attempts over a two‑week period, listing affected products but providing no deeper technical or patch details.

    070921.2K
    5.5K followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    A mass-scanning operation is exploiting exposed Vite development servers to retrieve cloud credentials, configuration data, and other secrets from AWS and Azure environments. - Attackers exploit CVE-2026-39364 by manipulating query parameters to bypass file-access restrictions and return protected files in plaintext. - Scanning targets environment files, AWS and Azure credentials, Terraform state, serverless configurations, process environment data, and system files, with traversal and encoding variants used to evade filtering. - F5 observed more than 800 attacks and approximately 32,000 events over one month; activity originated mainly from the United States, Belgium, and the Netherlands and used Google Cloud IP ranges. - Related activity also exploited CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811. Exposed servers should be patched and reachable secrets rotated.

    Post summary

    The report details a mass-scanning campaign exploiting CVE-2026-39364 in Vite development servers to exfiltrate cloud credentials, with observed attack statistics and a recommendation to patch exposed systems.

    0002081
    103 followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    Automated scanning in August 2026 increasingly exploited exposed Vite development servers to steal cloud credentials and deployment data. - Attackers abused CVE-2026-39364, an unauthenticated access-control bypass affecting specified Vite versions, by manipulating query parameters on the internal @ fs route. - Scanners also tested CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811 using extensive wordlists targeting environment files, AWS and Azure credential stores, Terraform state, serverless artifacts, and Linux process data. - Honeypot telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events; exposed files could enable cloud account takeover, lateral movement, or broader infrastructure compromise. VULNERABILITY CVE-2024-45811 CVE-2025-30208 CVE-2025-31125 CVE-2026-39364

    Post summary

    The report details active exploitation of exposed Vite development servers, including CVE-2026-39364 and other CVEs, with evidence from honeypot telemetry showing numerous attacks.

    0001044
    74 followersView on X
  • Divert@Divert_Security
    Active Exploitation

    @vite_js Improper access control CVE-2025-31125, just added by #CISA to #KEV on 1/22/26, detected and blocked by Divert when we deployed months ago. https://t.co/I7H5VgGJlt

    Post summary

    The tweet notes that CVE‑2025‑31125 was recently added to CISA’s KEV list, indicating it is being actively exploited, but no proof‑of‑concept, exploit code, patch, or detailed technical description is provided.

    0001030
    10 followersView on X
  • Breachrr@Breachrr
    Active Exploitation

    F5 honeypots recorded 807 session-grouped attacks and about 32,000 raw events against exposed Vite development servers in August. Vite-related file-read events across the prior three months totaled 1,732. The current payload is CVE-2026-39364, disclosed April 7. On Vite 7.1.0 before 7.3.2 and 8.0.0 before 8.0.5, appending ?raw, ?import&raw, or ?import&url&inline makes the server skip server.fs.deny and return the file as HTTP 200. The same fleet reused older Vite bypasses, including CVE-2025-31125. The wordlists were not looking for a homepage. They requested .env variants, AWS credential files under common home directories, Azure accessTokens.json, Terraform state, Serverless state, and /proc/self/cwd/.env. Vite binds to localhost unless someone passes --host, sets http://server.host, or publishes port 5173 from a container. That exposure is the access path. Patch the dev server. Take the listener off the internet. Rotate every secret that lived on that host.

    Post summary

    The text reports active exploitation of CVE-2026-39364 against exposed Vite development servers, describes the file‑read bypass technique, and urges patching and mitigation.

    0000075
    34 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day | 24-02-2026 Source: https://www.recordedfuture.com/blog/january-2026-cve-landscape Key details below ↓ 🧑‍💻Actors/Campaigns: Fancy_bear Neusploit 💀Threats: Nuclei_tool, Minidoor, Pixynetloader, Covenant_c2_tool, Grunt, Com_hijacking_technique, Supply_chain_technique, 🎯Victims: Enterprise communication platforms, Enterprise management platforms, Government users, Business users, Wordpress sites, Email systems 🏭Industry: Government 🌐Geo: Russian 🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-34026 \[[Vulners](https://vulners.com/cve/CVE-2025-34026)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - versa-networks concerto (<12.1.2, 12.2.0) CVE-2009-0556 \[[Vulners](https://vulners.com/cve/CVE-2009-0556)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft office_powerpoint (2004) - microsoft powerpoint (2000, 2002, 2003) CVE-2025-8110 \[[Vulners](https://vulners.com/cve/CVE-2025-8110)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - gogs (le0.13.3) CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-68645 \[[Vulners](https://vulners.com/cve/CVE-2025-68645)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - synacor zimbra_collaboration_suite (<10.0.18, <10.1.13) CVE-2018-14634 \[[Vulners](https://vulners.com/cve/CVE-2018-14634)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - paloaltonetworks pan-os (<7.1.23, <8.0.16, <8.1.7) CVE-2026-21509 \[[Vulners](https://vulners.com/cve/CVE-2026-21509)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - microsoft 365_apps (-) - microsoft office (2016, 2019) - microsoft office_long_term_servicing_channel (2021, 2024) CVE-2025-37164 \[[Vulners](https://vulners.com/cve/CVE-2025-37164)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - hpe oneview (le10.20.00) CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.7.0.0) CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0) CVE-2026-20045 \[[Vulners](https://vulners.com/cve/CVE-2026-20045)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - cisco unified_communications_manager (<14su5, le15su3a) - cisco unified_communications_manager_im_and_presence_service (<14su5, le15su3a) - cisco unity_connection (<14su5, le15su3) CVE-2026-20931 \[[Vulners](https://vulners.com/cve/CVE-2026-20931)] - CVSS V3.1: *8.0*, - Vulners: Exploitation: Unknown Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2026-20805 \[[Vulners](https://vulners.com/cve/CVE-2026-20805)] - CVSS V3.1: *5.5*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2025-52691 \[[Vulners](https://vulners.com/cve/CVE-2025-52691)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9413) CVE-2025-31125 \[[Vulners](https://vulners.com/cve/CVE-2025-31125)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - vitejs vite (<4.5.11, <5.4.16, <6.0.13, <6.1.3, <6.2.4) CVE-2026-24858 \[[Vulners](https://vulners.com/cve/CVE-2026-24858)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4) - fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3) ... CVE-2025-54313 \[[Vulners](https://vulners.com/cve/CVE-2025-54313)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - prettier eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7) CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) CVE-2026-20029 \[[Vulners](https://vulners.com/cve/CVE-2026-20029)] - CVSS V3.1: *4.9*, - Vulners: Exploitation: Unknown CVE-2026-23550 \[[Vulners](https://vulners.com/cve/CVE-2026-23550)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2026-23800 \[[Vulners](https://vulners.com/cve/CVE-2026-23800)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2024-37079 \[[Vulners](https://vulners.com/cve/CVE-2024-37079)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - vmware cloud_foundation (<5.2) CVE-2026-24061 \[[Vulners](https://vulners.com/cve/CVE-2026-24061)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - gnu inetutils (le2.7) 🤖LLM extracted TTPs:` T1005, T1027, T1053.005, T1071.001, T1078, T1090, T1098, T1112, T1114.003, T1133, ... 🧨IOCs: - Path: 2 - Registry: 1 - IP: 6 - Email: 4 - File: 2 💽Software: Microsoft Office, Ivanti, Linux, Zimbra Collaboration Suite, WordPress, Outlook, Ivanti EPMM 🔢Algorithms: xor 📜Programming Languages: php #threatreport: In January 2026, there was a noted 5% increase in critical vulnerabilities, with 23 high-impact issues identified. Among these, the exploitation of a significant Microsoft Office zero-day vulnerability (CVE-2026-21509) by Russian state-sponsored group APT28 highlighted ongoing threats to enterprise technologies. This vulnerability, which relates to the reliance on untrusted inputs in security decisions, enabled APT28 to utilize weaponized Rich Text Format (RTF) files to deliver various malicious implants, including MiniDoor, PixyNetLoader, and Covenant Grunt. The exploitation chain initiated with an RTF file that bypassed Office OLE mitigations. The attackers deployed MiniDoor as an Outlook VBA script for email collection, while PixyNetLoader, which created a mutex for persistence, allowed further attacks. A notable aspect of this operation was the use of geography-based evasion to limit the delivery of the malicious payloads, demonstrating the sophistication of the APT28 attacks. In addition to Microsoft, other vendors such as SmarterTools and Ivanti were significantly affected, with SmarterTools reporting multiple critical vulnerabilities allowing authentication bypass and remote code execution (RCE). Specifically, CVE-2026-23760 identified a privilege escalation flaw in SmarterMail, permitting unauthenticated users to reset passwords, demonstrating serious flaws in expected security protocols. Furthermore, the Modular DS WordPress plugin was found to have multiple vulnerabilities, CVE-2026-23550 and CVE-2026-23800, that allowed attackers to gain administrator access without authentication. These vulnerabilities emphasize the risk of widespread exploitation due to the centralized management of multiple WordPress sites.

    Post summary

    The report details APT28’s active exploitation of CVE-2026-21509 via weaponized RTF files, employing MiniDoor, PixyNetLoader, and Covenant Grunt, and highlights additional critical CVEs affecting Microsoft Office and other vendors.

    0000074
    589 followersView on X
  • Miguel Vera@mveracf
    Patch

    🛡️ Heads up! Cloudflare WAF is adding new protections against Zimbra &amp; Vite vulnerabilities (CVE-2025-68645 &amp; CVE-2025-31125) on Feb 9th. Stay secure with our proactive threat detection! 🚀 https://developers.cloudflare.com/changelog/scheduled-waf-release/

    Post summary

    Cloudflare has updated its WAF to protect against CVE-2025-68645 and CVE-2025-31125, offering proactive threat detection for users.

    0000071
    1 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Active Vite dev-server zero-day (CVE-2025-31125) leaks “denied” files via ?inline/?raw import bypass UpGuard reports active exploitation of CVE-2025-31125 in Vite where attackers can bypass `server.fs.deny` using query strings like `?inline&import` or `?raw&import` to expose sensitive files (configs/source/credentials) on dev servers mistakenly exposed to networks (`--host` / `http://server.host`). Patch to fixed releases (6.2.4 / 6.1.3 / 6.0.13 / 5.4.16 / 4.5.11) and ensure dev servers are not internet-reachable. 🎯 Target: Global/JavaScript Dev Environments (Vite dev servers) #️⃣ Category: #Vulnerability #CyberIntel #BlueTeam 🔗 URL: https://www.upguard.com/news/vitejs-data-breach-2026-01-23

    Post summary

    UpGuard confirms that CVE‑2025‑31125 is actively exploited by using query‑string bypasses to leak denied files from Vite dev servers, and patches are available for multiple releases.

    0000066
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvitejsvite-node.js-

Explore more