CVE-2025-31486

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 284
CWE ID 200

Summary

CVE-2025-31486 is a vulnerability affecting Vite, a popular frontend tooling framework for JavaScript. The issue allows an attacker to bypass the server's file denial restriction and retrieve the contents of arbitrary files smaller than 4kB, even if they are not intended for public access. This vulnerability is only exploitable when using Vite 6.0 or later and is caused by a misconfiguration when adding specific headers to requests. Only applications explicitly exposing the Vite dev server to the network are at risk. This issue has been addressed in versions 4.5.12, 5.4.17, 6.0.14, 6.1.4, and 6.2.5.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share