Beschreibung
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server-s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default -...-). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.
CVSS 7.5EPSS 3.319%Risiko 0.97
Quelle öffnen- Veröffentlicht
- 2026-04-07 20:16:30
- Betroffene Versionen
- >=6.0.0,<6.4.2,>=7.0.0,<7.3.2,>=8.0.0,<8.0.5
- Typ
- Package
- Zuletzt geändert
- 2026-08-04 13:18:24
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N