Executive brief
@vitejs/plugin-rsc is a React plugin for the Vite build tool used in web development. During development mode, an unauthenticated attacker can read any file accessible to the Node.js process by exploiting an unprotected endpoint, potentially exposing environment files, SSH keys, cloud credentials, database passwords, and source code. This risk is particularly acute when developers expose their dev servers to network access for mobile testing purposes.
Technical details
The vulnerability is a path traversal / arbitrary file read in the `/__vite_rsc_findSourceMapURL` endpoint, which accepts a user-controlled `filename` query parameter without validation. The vulnerable code converts any `file://` URL to a filesystem path using `fileURLToPath()` and reads the file with `fs.readFileSync()`, returning the full file contents in the JSON response's `sourcesContent` field. The attack requires network reachability to the dev server (typically localhost:5173) and no authentication. Exploitation is straightforward: an attacker crafts a simple HTTP GET request with a `file://` URL pointing to sensitive files like `/etc/passwd`, `.env` files, or SSH keys. The fix (version 0.5.8+) adds proper path validation to ensure only legitimate source files within the project directory are read.
Affected products
- Vitejs @vitejs/plugin-rsc <=0.5.7
Timeline
- 2025-12-16: disclosed
- 2025-12-16: patched: Version 0.5.8 released with path validation fix