Vulnerabilities/

Vite's `server.fs.deny` is bypassed when using `?import&raw`

Severity:
Medium

Description

The contents of arbitrary files can be returned to the browser.

Recommendation

Update the vite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vite
Anything's wrong? Let us know Last updated on September 19, 2024

This issue is available in SmartScanner Professional

See Pricing