Security Flaw in Vite Frontend Framework for JavaScript
CVE-2025-62522
6MEDIUM
What is CVE-2025-62522?
A vulnerability in the Vite frontend framework allows files specified in server.fs.deny to be transmitted when a URL ends with a backslash. This issue affects applications that expose the Vite development server to the network while running on Windows, enabling unauthorized access to restricted files. The vulnerability has been resolved in Vite versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.
Affected Version(s)
vite >= 7.1.0, < 7.1.11 < 7.1.0, 7.1.11
vite >= 7.0.0, < 7.0.8 < 7.0.0, 7.0.8
vite >= 6.0.0, < 6.4.1 < 6.0.0, 6.4.1