← voltar
CVE-2025-30208mediumexploração observadaCWE-200CWE-284

Vite bypasses server.fs.deny when using `?raw??`

97Vexday Risk Score

Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.

ssvc Actcvss 5.3epss 75%
da publicação à arma0 dias
Publicada no NVD24 de mar.
1ª PoC21 de mar.
VulnCheck+35d
probabilidade de exploração
75%top 1% das CVEs
exploração observada
simVulnCheck
52 exploit(s) público(s)
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Produtos afetados
vitejs · vite
PoCs públicas encontradas52
exploitdbwww.exploit-db.com/exploits/52111não verificadogithubgithub.com/ThumpBo/CVE-2025-30208-EXP196githubgithub.com/xuemian168/CVE-2025-3020848githubgithub.com/4xura/CVE-2025-3020810githubgithub.com/ThemeHackers/CVE-2025-3020810githubgithub.com/marino-admin/Vite-CVE-2025-30208-Scanner10githubgithub.com/jackieya/ViteVulScan7githubgithub.com/4m3rr0r/CVE-2025-30208-PoC7githubgithub.com/nkuty/CVE-2025-30208-31125-31486-323955githubgithub.com/On1onss/CVE-2025-302084githubgithub.com/r0ngy40/CVE-2025-30208-Series3githubgithub.com/imbas007/CVE-2025-30208-template1githubgithub.com/lilil3333/Vite-CVE-2025-30208-EXP1githubgithub.com/TH-SecForge/CVE-2025-302081githubgithub.com/keklick1337/CVE-2025-30208-ViteVulnScanner1githubgithub.com/sumeet-darekar/CVE-2025-302081githubgithub.com/sadhfdw129/CVE-2025-30208-Vite0githubgithub.com/Lusensec/CVE-2025-302080githubgithub.com/iSee857/CVE-2025-30208-PoC0githubgithub.com/MiclelsonCN/CVE-2025-30208_POC0githubgithub.com/HazaVVIP/CVE-2025-302080githubgithub.com/0xshaheen/CVE-2025-302080githubgithub.com/HaGsec/CVE-2025-302080githubgithub.com/cc3305/CVE-2025-302080vulncheckvulncheck.com/xdb/bb5065ec0b7anão verificadovulncheckvulncheck.com/xdb/41f5125956cbnão verificadovulncheckvulncheck.com/xdb/471869748223não verificadovulncheckvulncheck.com/xdb/e32d7a06be19não verificadovulncheckvulncheck.com/xdb/90a18ae15449não verificadovulncheckvulncheck.com/xdb/388dd832b246não verificadovulncheckvulncheck.com/xdb/5e7ec44b1362não verificadovulncheckvulncheck.com/xdb/2b49283dffeenão verificadovulncheckvulncheck.com/xdb/e33919a9052anão verificadovulncheckvulncheck.com/xdb/6cf8cde60cdenão verificadovulncheckvulncheck.com/xdb/24952455a76cnão verificadovulncheckvulncheck.com/xdb/548faa8fa166não verificadovulncheckvulncheck.com/xdb/17f3c0aa6eb8não verificadovulncheckvulncheck.com/xdb/c07d38ebc777não verificadovulncheckvulncheck.com/xdb/e32c52f19c5bnão verificadovulncheckvulncheck.com/xdb/80a9c1d50a28não verificadovulncheckvulncheck.com/xdb/9ec1c547aa75não verificadovulncheckvulncheck.com/xdb/d281d302d090não verificadovulncheckvulncheck.com/xdb/e849c744163enão verificadovulncheckvulncheck.com/xdb/116a9432fccanão verificadovulncheckvulncheck.com/xdb/7216ff7bdb87não verificadovulncheckvulncheck.com/xdb/573055c0e76anão verificadovulncheckvulncheck.com/xdb/461563839aeenão verificadovulncheckvulncheck.com/xdb/8ae6806b4071não verificadovulncheckvulncheck.com/xdb/c84cbb3fd16bnão verificadovulncheckvulncheck.com/xdb/108529b531b0não verificadovulncheckvulncheck.com/xdb/14e5ead281aenão verificadovulncheckvulncheck.com/xdb/5e5666f6e4b5não verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.