Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
History

Wed, 17 Sep 2025 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 15 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Vitejs
Vitejs vite
Vendors & Products Vitejs
Vitejs vite

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Sep 2025 23:00:00 +0000

Type Values Removed Values Added
Description Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
Title Vite middleware may serve files starting with the same name with the public directory
Weaknesses CWE-200
CWE-22
CWE-284
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-08T22:52:45.667Z

Updated: 2025-09-09T13:29:36.802Z

Reserved: 2025-09-04T19:18:09.499Z

Link: CVE-2025-58751

cve-icon Vulnrichment

Updated: 2025-09-09T13:14:15.540Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-08T23:15:36.170

Modified: 2025-09-17T16:21:36.240

Link: CVE-2025-58751

cve-icon Redhat

Severity : Low

Publid Date: 2025-09-08T22:52:45Z

Links: CVE-2025-58751 - Bugzilla