Vulnerabilities/

Vite allows server.fs.deny to be bypassed with .svg or relative paths

Severity:
Medium

Description

The contents of arbitrary files can be returned to the browser.

Recommendation

Update the vite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vite
Anything's wrong? Let us know Last updated on April 30, 2025

This issue is available in SmartScanner Professional

See Pricing