Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-58752

20
FAUCET Score

CVE-2025-58752 is a medium-severity vulnerability affecting Vite, a JavaScript frontend tooling framework, specifically versions prior to 7.1.5, 7.0.7, 6.3.6, and 5.4.20. It allows unauthenticated attackers to access arbitrary HTML files on the server, bypassing intended file system restrictions, when the Vite dev or preview server is exposed to the network and configured for SPA or MPA applications. The vulnerability has a CVSS score of 5.3 (Medium) due to its low attack complexity and network-based vector, potentially leading to information disclosure. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.4.20CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
>= 6.0.0, < 6.3.6CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
>= 7.0.0, < 7.0.7CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
>= 7.1.0, < 7.1.5CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

2.3LOW

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0059 is in the 28th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: viteFixed in: 7.1.5
npmpatch availablevia ghsa
Product: viteFixed in: 7.0.7
npmpatch availablevia ghsa
Product: viteFixed in: 6.3.6
npmpatch availablevia ghsa
Product: viteFixed in: 5.4.20
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-controller
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-eda-controller
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-gateway
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.keycloak-keycloak-parent
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.keycloak-keycloak-parent
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/traefik-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-agent-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-all-in-one-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-collector-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-es-index-cleaner-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-es-rollover-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-ingester-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-operator-bundle
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-query-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-rhel8-operator
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/tempo-jaeger-query-rhel8

Vendor Advisories (2)

npmGHSA-jqfw-vq24-v9c3low

Vite's `server.fs` settings were not applied to HTML files

Sep 9, 2025
redhatCVE-2025-58752Low

vite: Vite's `server.fs` settings were not applied to HTML files

Sep 8, 2025

References

github.com / vitejs/vite/commit/0ab19ea9fcb66f544328f442cf6e70f7c0528d5f
Patch
github.com / vitejs/vite/commit/14015d794f69accba68798bd0e15135bc51c9c1e
Patch
github.com / vitejs/vite/commit/482000f57f56fe6ff2e905305100cfe03043ddea
Patch
github.com / vitejs/vite/commit/6f01ff4fe072bcfcd4e2a84811772b818cd51fe6
Patch
github.com / vitejs/vite/security/advisories/GHSA-jqfw-vq24-v9c3
ExploitThird Party Advisory