Executive brief
Vite is a JavaScript build tool and development server. When exposed to the network (a non-default configuration), attackers can read sensitive files like .env containing credentials and private keys by using path traversal with a specially crafted request. This affects only development instances intentionally exposed to the network, allowing exposure of application secrets.
Technical details
This vulnerability is a path traversal / access control bypass in Vite's file serving restrictions. The server.fs.deny configuration option is meant to block access to sensitive files matching patterns like .env, *.crt, and *.pem. However, the pattern matching can be bypassed by appending /. to the request path (e.g., requesting /.env/. instead of /.env). An attacker with network access to a Vite dev server that has been explicitly exposed via --host or server.host configuration can read denied files under the project root. No authentication or user interaction is strictly required from the target system, though passive user interaction is noted in the CVSS metrics. Patches are available for all affected versions from 4.5.14 onwards.
Affected products
- Vite Vite <=4.5.13, 5.0.0-5.4.18, 6.0.0-6.1.5, 6.2.0-6.2.6, 6.3.0-6.3.3
Timeline
- 2025-04-30: disclosed
- 2025-05-01: advisory: NVD published