CVE Feed

    Dashboard / CVE / CVE-2025-30208

    CVE-2025-30208

    Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

    Published:Mar 24, 2025
    Last Modified:Sep 23, 2025
    EPS:Mar 24, 2025
    EPSS Score:0.83262
    CVSS Score:5.3

    Affected Products

    Vendor
    Vitejs
    Product
    Vite

    Exploits

    https://github.com/vitejs/vite/security/advisories/GHSA-x574-m823-4x7whttps://www.exploit-db.com/exploits/52111https://github.com/0xshaheen/CVE-2025-30208https://github.com/4m3rr0r/CVE-2025-30208-PoChttps://github.com/4xura/CVE-2025-30208https://github.com/Ashwesker/Blackash-CVE-2025-30208https://github.com/B1ack4sh/Blackash-CVE-2025-30208https://github.com/bugdotexe/CVE-2025-30208https://github.com/cc3305/CVE-2025-30208https://github.com/Dany60-98/CVE-2025-30208-EXPhttps://github.com/gonn4cry/CVE-2025-30208https://github.com/HaGsec/CVE-2025-30208https://github.com/HazaVVIP/CVE-2025-30208https://github.com/imbas007/CVE-2025-30208-templatehttps://github.com/iSee857/CVE-2025-30208-PoChttps://github.com/jackieya/ViteVulScanhttps://github.com/keklick1337/CVE-2025-30208-ViteVulnScannerhttps://github.com/kk12-30/CVE-2025-30208https://github.com/layanOd/CVE-2025-30208-Arbitrary-File-Read-in-Vite-servershttps://github.com/lilil3333/Vite-CVE-2025-30208-EXPhttps://github.com/Lusensec/CVE-2025-30208https://github.com/marino-admin/Vite-CVE-2025-30208-Scannerhttps://github.com/MiclelsonCN/CVE-2025-30208_POChttps://github.com/nkuty/CVE-2025-30208-31125-31486-32395https://github.com/On1onss/CVE-2025-30208https://github.com/On1onss/CVE-2025-30208-LFIhttps://github.com/qodo-dev/CVE-2025-30208https://github.com/r0ngy40/CVE-2025-30208-Serieshttps://github.com/sadhfdw129/CVE-2025-30208-Vitehttps://github.com/sumeet-darekar/CVE-2025-30208https://github.com/ThemeHackers/CVE-2025-30208https://github.com/TH-SecForge/CVE-2025-30208https://github.com/ThumpBo/CVE-2025-30208-EXPhttps://github.com/xaitx/CVE-2025-30208https://github.com/xuemian168/CVE-2025-30208https://github.com/YuanBenSir/CVE-2025-30208_POC

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High