CORS Misconfiguration in Vite Framework Affects WebSocket Security
CVE-2025-24010
What is CVE-2025-24010?
The Vite framework, a popular frontend tooling solution for JavaScript, has a security flaw that permits any website to send requests to its development server. This issue arises from default CORS settings and insufficient validation of the Origin header for WebSocket connections. As a result, sensitive data could potentially be exposed, enabling malicious actors to exploit this vulnerability. The issue has been addressed in versions 6.0.9, 5.4.12, and 4.5.6 as listed in the advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
vite >= 6.0.0, < 6.0.9 < 6.0.0, 6.0.9
vite >= 5.0.0, < 5.4.12 < 5.0.0, 5.4.12
vite < 4.5.6 < 4.5.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
