vite
101 known vulnerabilities · 0 critical · 1 high
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Websites were able to send any requests to the development server and read the response in vite
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
Vite's `server.fs.deny` did not deny requests for patterns with directories.
Vite: `server.fs.deny` bypassed with queries
Vite's server.fs.deny bypassed with /. for files under project root
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite's `server.fs.deny` is bypassed when using `?import&raw`
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Vite middleware may serve files starting with the same name with the public directory
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Malicious code in vite-plugin-svgn (npm)
Malicious code in vite-plugin-monorepo (npm)
Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
Malicious code in vite-dynachunk (npm)
@vitejs/plugin-rsc has a Denial of Service with React Server Components
Malicious code in @voiceflow/vitest-config (npm)
Malicious code in vite-plugin-esm-federation (npm)
Malicious code in vite_ruby_monorepo (npm)
Malicious code in vite-configs-viewer (npm)
Malicious code in vite-next-loggers (npm)
Malicious code in vite-plugin-httpfile (npm)
Malicious code in vite-compiler-tools (npm)
Malicious code in vite-smart-chunk (npm)
Malicious code in vite-binding-js (npm)
Malicious code in vite-plugin-compress-plus (npm)
Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components
Vite Plugin React has a Denial of Service Vulnerability in React Server Components
Malicious code in vite-plugin-parseflow (npm)
Malicious code in vite-plugin-postcss-tools (npm)
@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint
Malicious code in vite-chunk-tools (npm)
Malicious code in react-vite-sync (npm)
Malicious code in vite-config-pretty-js (npm)
Malicious code in vite-tsconfig-pretty (npm)
Malicious code in vite-plugin-svgr-logger (npm)
Malicious code in vite-css-icon (npm)
Malicious code in vitest-environment-jsdom-patched (npm)
Malicious code in vite-jsconfig-log (npm)
Malicious code in vite-plugin-uni-i18n (npm)
@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
Malicious code in vite-ui-components (npm)
TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction
Malicious code in template-vite (npm)
Malicious code in vite-plugin-esm-import-extension (npm)
Malicious code in aspirejavascript-vite (npm)
Malicious code in vite-loader-svg (npm)
Malicious code in vite-plugin-es6-compat (npm)
Malicious code in vite-postcss-tools (npm)
Malicious code in vite-plugin-parsify (npm)
Malicious code in vite-logify (npm)
Malicious code in vite-postcss-bootstrap (npm)
Malicious code in vitetest-lint (npm)
Malicious code in vitest-globals (npm)
Malicious code in vite-manual-chunker (npm)
Malicious code in vite-react-chunker (npm)
Malicious code in vite-logging-tool (npm)
Malicious code in vite-postcss-nested (npm)
Malicious code in @ensdomains/vite-plugin-i18next-loader (npm)
Malicious code in vitest-config (npm)
Malicious code in buildkite-test-collector-vitest-example (npm)
Malicious code in test-vite-favicons-inject (npm)
Malicious code in vite-plugin-vue-layout (npm)
Malicious code in vite-plugin-legacy-umd (npm)
Malicious code in react-server-dom-vite (npm)
Malicious code in vite-dynamic-chunks (npm)
Malicious code in vite-plugin-tools (npm)
Malicious code in @voiceflow/vite-config (npm)
Malicious code in vite-chunker (npm)
Malicious code in vite-plugin-style-svg (npm)
Malicious code in vite-plugin-unus-api-register (npm)
Malicious code in vite-tsconsole-log (npm)
Malicious code in vite-plugin-morgan (npm)
Malicious code in vite-linting-js (npm)
Malicious code in vite-plugin-parse-js (npm)
Malicious code in dragon0905-vite-tsconfig-assistant (npm)
Malicious code in vite-plugin-chunk-chop (npm)
Malicious code in vite-tsconfig-assistant (npm)
Malicious code in vite-plugin-opticompress (npm)
Malicious code in webpack-vite (npm)
Malicious code in vite-react-setting (npm)
Malicious code in vite-plugin-es6-babel (npm)
Malicious code in vite-plugin-parse (npm)
Malicious code in vite-babel-plugin-es6-promise (npm)
Malicious code in vite-plugin-purify (npm)
Malicious code in vite-logging-patcher (npm)
Malicious code in vite-plugin-node-modules-polyfills (npm)
Malicious code in vite-plugin-remove (npm)
Malicious code in vite-logging-patchers (npm)
Malicious code in dev-debugger-vite (npm)
Malicious code in node-vite-config (npm)
Malicious code in vite-jsconfig (npm)
Malicious code in vite-plugin-enhance (npm)
Malicious code in vite-paypal (npm)
Malicious code in vite-auditlog (npm)