CVE-2025-46565Disclosure(vitejs / vite)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. Only files that are under project root and are denied by a file matching pattern can be bypassed. `server.fs.deny` can contain patterns matching against files (by default it includes .env, .env.*, *.{crt,pem} as such patterns). These patterns were able to bypass for files under `root` by using a combination of slash and dot (/.). This issue has been patched in versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vite

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
vite

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-27: 1Technical Details · 2026-03-27: 103-27
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-46565 - medium 🚨 Vite Dev Server - Information Exposure > Vite is a frontend tooling framework for JavaScript. Before versions 6.3.4, 6.2.7, 6.... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-46565 @pdnuclei #NucleiTemplates #cve

    Post summary

    This tweet announces the CVE-2025-46565 vulnerability in Vite Dev Server, describing it as an information exposure affecting pre‑6.3.4 and pre‑6.2.7 releases, and provides a link to more details, but offers no PoC, exploit code, active exploitation, or patch information.

    01010255
    905 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvitejsvite-node.js-

Explore more