Executive brief
Vite is a popular build tool and development server used by web developers. When the dev server is exposed to the network, an attacker can bypass security restrictions and retrieve sensitive source map files (.map) from outside the project directory by injecting path traversal sequences into source map requests. This could expose source code or other sensitive information embedded in these files.
Technical details
The vulnerability is a path traversal (CWE-22) and information disclosure (CWE-200) flaw in Vite's dev server middleware that processes .map requests for optimized dependencies. The vulnerable component resolves file paths from URLs and calls readFile without restricting ../ segments, allowing attackers to escape the project root. Attack vector is network-based and requires no authentication or user interaction, but does require two preconditions: (1) the dev server must be explicitly exposed to the network via --host or server.host configuration, and (2) sensitive .map files with predictable paths must exist outside the project. An attacker can craft requests to /@vite-optimized-deps/<relative-path>/.map with traversal sequences to read arbitrary .map files. Patches are available in versions 6.4.2, 7.3.2, and 8.0.5.
Affected products
- Vite Vite 6.4.1 and earlier, 7.0.0 through 7.3.1, 8.0.0 through 8.0.4
- npm vite-plus 0.1.15 and earlier
Timeline
- 2026-04-06: disclosed: Vulnerability disclosed via GitHub Advisory GHSA-4w7w-66w2-5vf9
- 2026-04-06: patched: Patches released: Vite 6.4.2, 7.3.2, 8.0.5
References
- https://github.com/vitejs/vite/security/advisories/GHSA-4w7w-66w2-5vf9
- https://github.com/vitejs/vite/pull/22161
- https://github.com/vitejs/vite/commit/79f002f2286c03c88c7b74c511c7f9fc6dc46694
- https://github.com/vitejs/vite
- https://github.com/vitejs/vite/releases/tag/v6.4.2
- https://github.com/vitejs/vite/releases/tag/v7.3.2