Vulnerabilities/

Websites were able to send any requests to the development server and read the response in vite

Severity:
Medium

Description

Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections.

Recommendation

Update the vite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vite
Anything's wrong? Let us know Last updated on February 07, 2025

This issue is available in SmartScanner Professional

See Pricing