vite
135 known vulnerabilities · 0 critical · 1 high
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Websites were able to send any requests to the development server and read the response in vite
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite's `server.fs.deny` is bypassed when using `?import&raw`
Vite's server.fs.deny bypassed with /. for files under project root
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Vite middleware may serve files starting with the same name with the public directory
Vite's `server.fs.deny` did not deny requests for patterns with directories.
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
vite: `server.fs.deny` bypass on Windows alternate paths
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
launch-editor vulnerable to command injection via the crafted request on Windows
Vite: `server.fs.deny` bypassed with queries
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Malicious code in vite-plugin-svgn (npm)
Malicious code in vite-plugin-purify (npm)
Malicious code in vite-plugin-es6-babel (npm)
Malicious code in dev-debugger-vite (npm)
Malicious code in vite-plugin-monorepo (npm)
Malicious code in vite-svgr (npm)
Malicious code in vite-plugin-compress-js (npm)
Malicious code in vite-plugin-logo (npm)
Malicious code in template-vite (npm)
Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
Malicious code in vite-dynachunk (npm)
@vitejs/plugin-rsc has a Denial of Service with React Server Components
Malicious code in vite-plugin-esm-federation (npm)
Malicious code in vite_ruby_monorepo (npm)
Malicious code in vite-configs-viewer (npm)
Malicious code in vite-next-loggers (npm)
Malicious code in vite-plugin-httpfile (npm)
Malicious code in vite-compiler-tools (npm)
Malicious code in vite-smart-chunk (npm)
Malicious code in vite-binding-js (npm)
Malicious code in vite-plugin-compress-plus (npm)
Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components
Vite Plugin React has a Denial of Service Vulnerability in React Server Components
Malicious code in vite-plugin-parseflow (npm)
Malicious code in vite-plugin-postcss-tools (npm)
@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint
Malicious code in vite-chunk-tools (npm)
Malicious code in react-vite-sync (npm)
Malicious code in vite-config-pretty-js (npm)
Malicious code in vite-tsconfig-pretty (npm)
Malicious code in vite-plugin-svgr-logger (npm)
Malicious code in vite-css-icon (npm)
Malicious code in vitest-environment-jsdom-patched (npm)
Malicious code in vite-jsconfig-log (npm)
Malicious code in autotel-vitest (npm)
Malicious code in eslint-plugin-executable-stories-vitest (npm)
Malicious code in executable-stories-vitest (npm)
Malicious code in node-env-resolver-vite (npm)
Malicious code in vite-plugin-uni-i18n (npm)
Malicious code in vite-ui-components (npm)
Malicious code in vite-plugin-esm-import-extension (npm)
Malicious code in aspirejavascript-vite (npm)
Malicious code in vite-plugin-enhance (npm)
Malicious code in vite-loader-svg (npm)
Malicious code in vite-plugin-es6-compat (npm)
Malicious code in vite-postcss-tools (npm)
Malicious code in vite-plugin-parsify (npm)
Malicious code in vite-logify (npm)
Malicious code in vite-postcss-bootstrap (npm)
Malicious code in vitetest-lint (npm)
Malicious code in vite-manual-chunker (npm)
Malicious code in vite-react-chunker (npm)
Malicious code in vite-postcss-nested (npm)
Malicious code in @ensdomains/vite-plugin-i18next-loader (npm)
Malicious code in vite-logging-tool (npm)
Malicious code in vitest-config (npm)
Malicious code in vite-plugin-parse (npm)
Malicious code in vite-plugin-env-compat-1.5 (npm)
Malicious code in vite-plugin-env-compat-plus (npm)
Malicious code in vitest-globals (npm)
Malicious code in buildkite-test-collector-vitest-example (npm)
Malicious code in @tanstack/nitro-v2-vite-plugin (npm)
Malicious code in @tanstack/router-vite-plugin (npm)
Malicious code in test-vite-favicons-inject (npm)
Malicious code in @tailwind-core/vite (npm)
Malicious code in vite-plugin-vue-layout (npm)
Malicious code in vite-plugin-legacy-umd (npm)
Malicious code in chai-as-vite (npm)
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Malicious code in vite-json-config (npm)
Malicious code in vite-plugin-css-blend (npm)
Malicious code in vite-configu-react (npm)
Malicious code in vite-enhancer-config (npm)
Malicious code in react-server-dom-vite (npm)
Malicious code in vitest-pro (npm)
Malicious code in vite-plugin-tools (npm)
Malicious code in @voiceflow/vite-config (npm)
Malicious code in vite-chunker (npm)
Malicious code in vite-plugin-style-svg (npm)
Malicious code in vite-plugin-unus-api-register (npm)
Malicious code in vite-tsconsole-log (npm)
Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
Malicious code in vite-plugin-morgan (npm)
When Vitest UI server is listening, arbitrary file can be read and executed
TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction
Nuxt dev server vite-node IPC socket is world-connectable on Linux
Malicious code in dragon0905-vite-tsconfig-assistant (npm)
Malicious code in vite-tsconfig-assistant (npm)
Malicious code in vite-plugin-opticompress (npm)
Malicious code in vite-linting-js (npm)
Malicious code in vite-plugin-parse-js (npm)
@vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components
Malicious code in vite-react-setting (npm)
Malicious code in webpack-vite (npm)
Malicious code in vite-plugin-chunk-chop (npm)
Malicious code in vite-babel-plugin-es6-promise (npm)
Malicious code in vite-logging-patcher (npm)
Malicious code in vite-plugin-node-modules-polyfills (npm)
Malicious code in vite-plugin-remove (npm)
Malicious code in vite-config-field (npm)
Malicious code in vite-logging-patchers (npm)
Malicious code in node-vite-config (npm)
Malicious code in vite-jsconfig (npm)
Malicious code in vite-auditlog (npm)
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
Malicious code in vite-tsconfig (npm)
Malicious code in react-vite-assert (npm)
Malicious code in vite-react-toolkit (npm)
Malicious code in vite-config-optimizer (npm)
Malicious code in vite-config-react (npm)
Malicious code in @voiceflow/vitest-config (npm)
Malicious code in vite-dynamic-chunks (npm)
Malicious code in vite-paypal (npm)
Malicious code in vite-common-utils (npm)