Vulnerabilities/

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

Severity:
Medium

Description

The contents of arbitrary files can be returned to the browser.

Recommendation

Update the vite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vite
Anything's wrong? Let us know Last updated on March 31, 2025

This issue is available in SmartScanner Professional

See Pricing