Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-58751

Опубликовано: 08 сент. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the server.fs settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
Версия до 5.4.20 (исключая)
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
Версия от 6.0.0 (включая) до 6.3.6 (исключая)
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
Версия от 7.0.0 (включая) до 7.0.7 (исключая)
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
Версия от 7.1.0 (включая) до 7.1.5 (исключая)

EPSS

Процентиль: 84%
0.02086
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.7
redhat
3 месяца назад

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.

CVSS3: 5.3
debian
3 месяца назад

Vite is a frontend tooling framework for JavaScript. Prior to versions ...

github
3 месяца назад

Vite middleware may serve files starting with the same name with the public directory

EPSS

Процентиль: 84%
0.02086
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22