Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
History

Mon, 08 Sep 2025 23:00:00 +0000

Type Values Removed Values Added
Description Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
Title Vite middleware may serve files starting with the same name with the public directory
Weaknesses CWE-200
CWE-22
CWE-284
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-08T22:52:45.667Z

Reserved: 2025-09-04T19:18:09.499Z

Link: CVE-2025-58751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-08T23:15:36.170

Modified: 2025-09-08T23:15:36.170

Link: CVE-2025-58751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.