Security Flaw in Vite Frontend Framework for JavaScript
CVE-2025-62522

6MEDIUM

Key Information:

Vendor

Vitejs

Status
Vendor
CVE Published:
20 October 2025

What is CVE-2025-62522?

A vulnerability in the Vite frontend framework allows files specified in server.fs.deny to be transmitted when a URL ends with a backslash. This issue affects applications that expose the Vite development server to the network while running on Windows, enabling unauthorized access to restricted files. The vulnerability has been resolved in Vite versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.

Affected Version(s)

vite >= 7.1.0, < 7.1.11 < 7.1.0, 7.1.11

vite >= 7.0.0, < 7.0.8 < 7.0.0, 7.0.8

vite >= 6.0.0, < 6.4.1 < 6.0.0, 6.4.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62522 : Security Flaw in Vite Frontend Framework for JavaScript