Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
History

Wed, 17 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 15 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Vitejs
Vitejs vite
Vendors & Products Vitejs
Vitejs vite

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Description Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
Title Vite's `server.fs` settings were not applied to HTML files
Weaknesses CWE-200
CWE-23
CWE-284
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-08T22:56:58.039Z

Updated: 2025-09-09T13:29:30.868Z

Reserved: 2025-09-04T19:18:09.499Z

Link: CVE-2025-58752

cve-icon Vulnrichment

Updated: 2025-09-09T13:13:55.264Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-08T23:15:36.350

Modified: 2025-09-17T16:12:20.913

Link: CVE-2025-58752

cve-icon Redhat

Severity : Low

Publid Date: 2025-09-08T22:56:58Z

Links: CVE-2025-58752 - Bugzilla