Vitejs
Vitejs Vite: vulnerabilidades y CVE
Vitejs Vite tiene 26 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses7
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-31125 | Alta (7.5) | 65% | ⚠ Explotación activa | 31 mar 2025 | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71319 | Crítica (9.6) | 0.63% | — | 5 ago 2026 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On… |
| CVE-2026-53571 | Alta (8.2) | 0.58% | — | 22 jun 2026 | Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies… |
| CVE-2024-52011 | Alta (7.5) | 0.51% | — | 1 jun 2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute… |
| CVE-2026-39365 | Media (6.3) | 0.98% | — | 7 abr 2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without… |
| CVE-2026-39364 | Alta (8.2) | 1.5% | — | 7 abr 2026 | Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200… |
| CVE-2026-39363 | Alta (8.2) | 2.6% | — | 7 abr 2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke… |
| CVE-2025-62522 | Media (6) | 1.1% | — | 20 oct 2025 | Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0… |
| CVE-2025-59330 | Alta (8.8) | 0.41% | — | 15 sept 2025 | error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the… |
| CVE-2025-59141 | Alta (8.8) | 0.41% | — | 15 sept 2025 | simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous… |
| CVE-2025-59140 | Alta (8.8) | 0.41% | — | 15 sept 2025 | backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous… |
| CVE-2025-59145 | Alta (8.8) | 0.55% | — | 15 sept 2025 | color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch… |
| CVE-2025-58751 | Baja (2.3) | 1.2% | — | 8 sept 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only… |
| CVE-2025-58752 | Baja (2.3) | 0.61% | — | 8 sept 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose… |
| CVE-2025-46565 | Media (6) | 1.2% | — | 1 may 2025 | Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the… |
| CVE-2025-32395 | Media (6) | 1.7% | — | 10 abr 2025 | Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP… |
| CVE-2025-31486 | Media (5.3) | 40% | — | 3 abr 2025 | Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction… |
| CVE-2025-31125 | Alta (7.5) | 65% | ⚠ Explotación activa | 31 mar 2025 | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or… |
| CVE-2025-30208 | Alta (7.5) | 75% | — | 24 mar 2025 | Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or… |
| CVE-2025-24010 | Media (6.5) | 0.29% | — | 20 ene 2025 | Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin… |
| CVE-2024-45812 | Media (6.4) | 0.64% | — | 17 sept 2024 | Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. The DOM Clobbering… |
| CVE-2024-45811 | Media (4.8) | 1.1% | — | 17 sept 2024 | Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding… |
| CVE-2024-31207 | Media (5.9) | 0.71% | — | 4 abr 2024 | Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This… |
| CVE-2024-23331 | Alta (7.5) | 0.78% | — | 19 ene 2024 | Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers… |
| CVE-2023-49293 | Media (6.1) | 1.00% | — | 4 dic 2023 | Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains… |
| CVE-2023-34092 | Alta (7.5) | 3.1% | — | 1 jun 2023 | Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to… |
| CVE-2022-35204 | Media (4.3) | 1.3% | — | 18 ago 2022 | Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.