CVE-2025-31486
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-31486 is a vulnerability affecting Vite, a popular frontend tooling framework for JavaScript. The issue allows an attacker to bypass the server's file denial restriction and retrieve the contents of arbitrary files smaller than 4kB, even if they are not intended for public access. This vulnerability is only exploitable when using Vite 6.0 or later and is caused by a misconfiguration when adding specific headers to requests. Only applications explicitly exposing the Vite dev server to the network are at risk. This issue has been addressed in versions 4.5.12, 5.4.17, 6.0.14, 6.1.4, and 6.2.5.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Vitejs Vite
Affected Vendors
- Vitejs