CVE-2025-31125
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 200
CWE ID 284
Summary
CVE-2025-31125 is a vulnerability affecting Vite, a frontend tooling framework for JavaScript. The issue allows unauthorized access to the content of non-allowed files through the use of specific import methods, ?inline&import or ?raw?import. This vulnerability only impacts apps that expose the Vite development server to the network, either through the --host or server.host configuration options. The vulnerability has been addressed in versions 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Vitejs Vite
Affected Vendors
- Vitejs