vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 21 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2. | |
Title | vite-plugin-static-copy files not included in `src` are accessible with a crafted request | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-21T16:03:04.804Z
Updated: 2025-08-21T17:32:07.786Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57753

Updated: 2025-08-21T17:24:16.374Z

Status : Received
Published: 2025-08-21T16:15:34.823
Modified: 2025-08-21T18:15:35.470
Link: CVE-2025-57753

No data.