Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
History

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Vitejs
Vitejs vite
Vendors & Products Vitejs
Vitejs vite

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Description Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
Title Vite's `server.fs` settings were not applied to HTML files
Weaknesses CWE-200
CWE-23
CWE-284
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-08T22:56:58.039Z

Updated: 2025-09-09T13:29:30.868Z

Reserved: 2025-09-04T19:18:09.499Z

Link: CVE-2025-58752

cve-icon Vulnrichment

Updated: 2025-09-09T13:13:55.264Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-08T23:15:36.350

Modified: 2025-09-09T16:28:43.660

Link: CVE-2025-58752

cve-icon Redhat

No data.