22 Total advisories
22 Vulnerabilities
0 Malware

Dependency scanning

Check whether vite is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2024-52011

launch-editor vulnerable to command injection via the crafted request on Windows

UNKNOWN
npm

CVE-2026-39363

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

UNKNOWN
npm

CVE-2025-32395

Vite has an `server.fs.deny` bypass with an invalid `request-target`

MEDIUM 5.3
npm KEV

CVE-2025-31125

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

UNKNOWN
npm

CVE-2026-53632

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

HIGH 7.5
npm

CVE-2026-53571

vite: `server.fs.deny` bypass on Windows alternate paths

UNKNOWN
npm

CVE-2026-39364

Vite: `server.fs.deny` bypassed with queries

UNKNOWN
npm

CVE-2026-39365

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

UNKNOWN
npm

CVE-2025-62522

vite allows server.fs.deny bypass via backslash on Windows

UNKNOWN
npm

CVE-2025-58752

Vite's `server.fs` settings were not applied to HTML files

UNKNOWN
npm

CVE-2025-58751

Vite middleware may serve files starting with the same name with the public directory

UNKNOWN
npm

CVE-2025-46565

Vite's server.fs.deny bypassed with /. for files under project root

MEDIUM 5.3
npm

CVE-2025-30208

Vite bypasses server.fs.deny when using ?raw??

MEDIUM 6.5
npm

CVE-2025-24010

Websites were able to send any requests to the development server and read the response in vite

MEDIUM 6.4
npm

CVE-2024-45812

Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS

MEDIUM 5.3
npm

CVE-2024-45811

Vite's `server.fs.deny` is bypassed when using `?import&raw`

MEDIUM 5.9
npm

CVE-2024-31207

Vite's `server.fs.deny` did not deny requests for patterns with directories.

HIGH 7.5
npm

CVE-2023-34092

Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)

MEDIUM 5.3
npm

CVE-2025-31486

Vite allows server.fs.deny to be bypassed with .svg or relative paths

HIGH 7.5
npm

CVE-2024-23331

Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

HIGH 8.6
npm

CVE-2022-35204

Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service

MEDIUM 6.1
npm

CVE-2023-49293

Vite XSS vulnerability in `server.transformIndexHtml` via URL payload

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes