CVE-2025-31125 Information

Description

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using –host or server.host config option) are affected. This vulnerability is fixed in 6.2.4 6.1.3 6.0.13 5.4.16 and 4.5.11.

Reference

https://github.com/vitejs/vite/commit/59673137c45ac2bcfad1170d954347c1a17ab949 https://github.com/vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8 https://github.com/vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8

Share on: