Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vitejs
Vitejs vite |
|
Vendors & Products |
Vitejs
Vitejs vite |
Tue, 09 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 08 Sep 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue. | |
Title | Vite's `server.fs` settings were not applied to HTML files | |
Weaknesses | CWE-200 CWE-23 CWE-284 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-08T22:56:58.039Z
Updated: 2025-09-09T13:29:30.868Z
Reserved: 2025-09-04T19:18:09.499Z
Link: CVE-2025-58752

Updated: 2025-09-09T13:13:55.264Z

Status : Awaiting Analysis
Published: 2025-09-08T23:15:36.350
Modified: 2025-09-09T16:28:43.660
Link: CVE-2025-58752

No data.