Junglewise Threat Intelligence

CVE-2025-46565: Vite server.fs.deny bypass with /. path traversal

CVE-2025-46565 · Severity: medium · CVSS 4 · Published 2025-04-30

Technologies: Vite. Vendors: Vite.

Executive brief

Vite is a JavaScript build tool and development server. When exposed to the network (a non-default configuration), attackers can read sensitive files like .env containing credentials and private keys by using path traversal with a specially crafted request. This affects only development instances intentionally exposed to the network, allowing exposure of application secrets.

Technical details

This vulnerability is a path traversal / access control bypass in Vite's file serving restrictions. The server.fs.deny configuration option is meant to block access to sensitive files matching patterns like .env, *.crt, and *.pem. However, the pattern matching can be bypassed by appending /. to the request path (e.g., requesting /.env/. instead of /.env). An attacker with network access to a Vite dev server that has been explicitly exposed via --host or server.host configuration can read denied files under the project root. No authentication or user interaction is strictly required from the target system, though passive user interaction is noted in the CVSS metrics. Patches are available for all affected versions from 4.5.14 onwards.

Affected products

  • Vite Vite <=4.5.13, 5.0.0-5.4.18, 6.0.0-6.1.5, 6.2.0-6.2.6, 6.3.0-6.3.3

Timeline

  • 2025-04-30: disclosed
  • 2025-05-01: advisory: NVD published

References

Related threats