EXPOSURES › CVE-2025-31125
CVE-2025-31125
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatched
Vitejs improper access control exposed non-allowed files via dev server
Vitejs allowed unauthorized access to its development server, potentially exposing sensitive files. Only those explicitly exposing the server to the network were affected.
Shame score — Highly negligent, intentionally exposed dev server to unauthorized access
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.