CVE-2025-31125
KEVHIGH 7.5EPSS 58.5%
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS
- 58.46% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2026-01-22
- Nuclei
- medium · CWE-200
- Published
- 2025-03-31
- Updated
- 2026-01-23
Proof-of-concept exploits (8)
- vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8
- advisories/GHSA-4r4m-qw57-chr8
- 0xgh057r3c0n/CVE-2025-311250★ · 2025-08-13
- MuhammadWaseem29/Vitejs-exploit0★ · 2025-05-03
- TehanG07/Vitejs-exploit1★ · 2025-05-17
- harshgupptaa/Path-Transversal-CVE-2025-31125-0★ · 2025-07-13
- khadafigans/Vite-Exploit3★ · 2025-10-04
- sunhuiHi666/CVE-2025-311256★ · 2025-04-01