Vite is a modestly represented but prominently deployed build tool and development server widely used across modern JavaScript and TypeScript projects, creating exposure concentrated in a single product. The vendor's disclosures recur around information-exposure, access-control, and path-traversal weaknesses characteristic of file-serving and development-environment tooling, and frequently acquire public exploit code. Defenders tracking development infrastructure should monitor this vendor's releases closely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vitejs over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31125HIGH Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev serve | Mar 31, 2025 | 7.5 | 92 | YES | YES |
CVE-2025-30208HIGH Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite se | Mar 24, 2025 | 7.5 | 84 | NO | YES |
CVE-2026-39364HIGH Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-39363HIGH Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2023-34092HIGH Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash ( | Jun 1, 2023 | 7.5 | 38 | NO | YES |
CVE-2026-53571HIGH Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on | Jun 22, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-39365MEDIUM Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves fi | Apr 7, 2026 | 5.3 | 31 | NO | YES |
CVE-2025-58751MEDIUM Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypa | Sep 8, 2025 | 5.3 | 30 | NO | YES |
CVE-2023-49293MEDIUM Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the | Dec 4, 2023 | 6.1 | 29 | NO | YES |
CVE-2025-46565MEDIUM Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file | May 1, 2025 | 5.3 | 27 | NO | YES |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vitejs.
Media articles that mention a CVE ID that affects a product developed by Vitejs — matched by CVE ID, not by vendor name.