Security: vitejs/vite
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
`server.fs.deny` bypass on Windows alternate pathsGHSA-fx2h-pf6j-xcff published
Jun 1, 2026 by sapphi-redHigh -
Path Traversal in Optimized Deps `.map` HandlingGHSA-4w7w-66w2-5vf9 published
Apr 6, 2026 by sapphi-redModerate -
`server.fs.deny` bypassed with queriesGHSA-v2wj-q39q-566r published
Apr 6, 2026 by sapphi-redHigh -
Arbitrary File Read via Vite Dev Server WebSocketGHSA-p9ff-h696-f583 published
Apr 6, 2026 by sapphi-redHigh -
`server.fs.deny` bypassed with `\` on WindowsGHSA-93m4-6634-74q7 published
Oct 20, 2025 by sapphi-redModerate -
Files starting with the same name with the public directory were servedGHSA-g4jq-h2w9-997c published
Sep 8, 2025 by sapphi-redLow -
`server.fs` settings was not applied to HTML filesGHSA-jqfw-vq24-v9c3 published
Sep 8, 2025 by sapphi-redLow -
`server.fs.deny` bypassed with `/.` for files under project `root`GHSA-859w-5945-r5v3 published
Apr 30, 2025 by sapphi-redModerate -
`server.fs.deny` bypassed with an invalid `request-target`GHSA-356w-63v5-8wf4 published
Apr 10, 2025 by sapphi-redModerate -
`server.fs.deny` bypassed with `.svg` or relative pathsGHSA-xcj6-pq6g-qj4x published
Apr 3, 2025 by patak-catModerate