Junglewise Threat Intelligence

CVE-2025-30208: Vite access control bypass in server.fs.deny with query parameters

CVE-2025-30208 · Severity: low · CVSS 3.1 · Published 2025-03-25

Technologies: Vite. Vendors: Vite.

Executive brief

Vite is a popular JavaScript build tool and development server used to build web applications. When a developer explicitly exposes the Vite dev server to the network, attackers can craft malicious URLs with specific query parameters to read arbitrary files from the host system, bypassing intended file access restrictions. This could expose sensitive source code, configuration files, or other confidential data to unauthorized parties.

Technical details

The vulnerability is an access control bypass (CWE-284) in Vite's server.fs.deny file access restrictions. The @fs virtual module is designed to restrict which files developers can serve, but the implementation fails to account for trailing query parameter separators (?) in its URL validation regex. By appending ?raw?? or ?import&raw?? to file paths in the @fs module, attackers can bypass the restriction check and retrieve file contents. The flaw requires the dev server to be explicitly exposed to the network (via --host or server.host config), and user interaction (crafting a request), but no authentication. Multiple versions are affected: all versions prior to 4.5.10, and versions 5.0.0–5.4.14, 6.0.0–6.0.11, 6.1.0–6.1.1, and 6.2.0–6.2.2. Patches are available.

Affected products

  • Vite Vite before 4.5.10; 5.0.0 through 5.4.14; 6.0.0 through 6.0.11; 6.1.0 through 6.1.1; 6.2.0 through 6.2.2

Timeline

  • 2025-03-24: disclosed: Published on NVD
  • 2025-03-25: advisory: Advisory published by GitHub (GHSA-x574-m823-4x7w)

References

Related threats