Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue. | |
Title | Vite's `server.fs` settings were not applied to HTML files | |
Weaknesses | CWE-200 CWE-23 CWE-284 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-08T22:56:58.039Z
Reserved: 2025-09-04T19:18:09.499Z
Link: CVE-2025-58752

No data.

Status : Received
Published: 2025-09-08T23:15:36.350
Modified: 2025-09-08T23:15:36.350
Link: CVE-2025-58752

No data.

No data.