CVE-2023-34092 is a path traversal vulnerability in Vite, affecting versions prior to 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9. This flaw allows unauthenticated attackers to bypass server.fs.deny configurations using double forward-slashes (//) and read sensitive files, such as .env or certificate files, from the project root. This vulnerability specifically impacts development servers explicitly exposed to the network via the --host or server.host option, limiting exposure to files within the immediate Vite project directory. Rated with a CVSSv3 score of 7.5 (High), the vulnerability has a network attack vector, low complexity, and requires no privileges or user interaction, leading to a high impact on confidentiality. While not listed on CISA's KEV catalog, the vulnerability is marked as "Active" on some hotlists, and community discussions indicate the existence of exploit code, including Nuclei templates, demonstrating active interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.2, < 3.2.7CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.0.5CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 4.1.0, < 4.1.5CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 4.2.0, < 4.2.3CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 4.3.0, < 4.3.9CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.