Junglewise Threat Intelligence

CVE-2025-67489: Vitejs plugin-rsc code injection in development server

CVE-2025-67489 · Severity: low · CVSS 3.1 · Published 2025-12-08

Technologies: @vitejs/plugin-rsc (npm), Vitejs Plugin-Rsc. Vendors: npm.

Executive brief

@vitejs/plugin-rsc is a Vite plugin for building React Server Components (RSC) applications. Attackers with network access to the development server can execute arbitrary JavaScript code with Node.js privileges by injecting malicious code through RSC server function APIs, allowing them to read files, steal credentials and environment variables, or compromise other services on the developer's network.

Technical details

This is a code injection vulnerability (CWE-94) in the @vitejs/plugin-rsc development server caused by unsafe dynamic imports in RSC server function APIs (loadServerAction, decodeReply, decodeAction). The vulnerable code accepts user-controlled input from HTTP request headers and form data and passes it directly to JavaScript's import() function without validation, allowing attackers to load arbitrary modules including data URLs containing malicious code. The attack requires network access to a development server running on a network-reachable interface (especially with vite --host), with no authentication or user interaction required. An attacker can craft a POST request to the /_.rsc endpoint with specially crafted payloads to execute arbitrary Node.js code. The vulnerability is fixed in version 0.5.6.

Affected products

  • Vitejs plugin-rsc <= 0.5.5

Timeline

  • 2025-12-08: disclosed
  • 2025-12-08: patched: Fix released in version 0.5.6
  • 2025-12-09: advisory

References

Related threats