MEDIUM🇵🇱 Wersja polska

CVE-2025-24010

CVSS 6.5v3.1pub. 2025-01-20upd. 2025-09-19

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • Vitejs Vite

    APP
    Vitejs
    < 4.5.55.0.0 – 5.4.12 (excl.)6.0.0 – 6.0.9 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-53571HIGH8.2same product

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files ...

CVE-2026-39364HIGH8.2same product

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev ser...

CVE-2026-39363HIGH8.2same product

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is po...

CVE-2024-23331HIGH7.5same product

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypass...

CVE-2023-34092HIGH7.5same product

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server O...