CVE-2025-58752Medium· 5.3▾ SunlitVite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev serve…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the server.fs settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use appType: 'spa' (default) or appType: 'mpa' are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
vite < 5.4.20vite >= 6.0.0, < 6.3.6vite >= 7.0.0, < 7.0.7vite >= 7.1.0, < 7.1.5Upgrade past the affected range:
vite 7.1.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39364High· 7.5Vite is a frontend tooling framework for JavaScript
CVE-2026-39363High· 7.5Vite is a frontend tooling framework for JavaScript
CVE-2026-53571Highvite: `server.fs.deny` bypass on Windows alternate paths
CVE-2025-10321Medium· 5.3A flaw has been found in Wavlink WL-WN578W2 221110
CVE-2025-59434Critical· 9.6Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-102845Medium· 5.3A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8