Vulnerabilities/

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

Severity:
High

Description

server.fs check was not enforced to the fetchModule method that is exposed in Vite dev server’s WebSocket.

Recommendation

Update the vite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vite
Anything's wrong? Let us know Last updated on April 07, 2026