Executive brief
Vite, a popular frontend development tool, contains a vulnerability that allows unauthorized access to files on a developer's machine. If a developer has configured the Vite development server to be accessible over a network, an attacker could remotely read sensitive files like system passwords or configuration files. This issue specifically affects developers using Node.js or Bun as their runtime environment.
Technical details
A path traversal and security bypass vulnerability exists in the Vite development server's handling of HTTP request targets. The Vite server failed to properly account for the '#' character in the request URL when validating paths against the 'server.fs.deny' configuration. While the HTTP/1.1 and HTTP/2 specifications generally prohibit '#' in the request-target, runtimes like Node.js and Bun pass these invalid targets to the application layer without rejection. An attacker can craft a request using an invalid target (e.g., including '/#/../../') to bypass filesystem restrictions and read arbitrary files from the host. This vulnerability affects Vite dev servers explicitly exposed to the network (via --host) running on Node or Bun; Deno is not affected as it handles the URL differently. The issue is fixed in versions 4.5.13, 5.4.18, 6.0.15, 6.1.5, and 6.2.6.
Affected products
- vitejs vite < 4.5.13, >= 5.0.0, < 5.4.18, >= 6.0.0, < 6.0.15, >= 6.1.0, < 6.1.5, >= 6.2.0, < 6.2.6
Timeline
- 2025-04-10: advisory
- 2025-04-11: disclosed