22 Total advisories
22 Vulnerabilities
0 Malware
Dependency scanning
Check whether vite is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2024-52011
launch-editor vulnerable to command injection via the crafted request on Windows
UNKNOWN
CVE-2026-39363
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
UNKNOWN
CVE-2025-32395
Vite has an `server.fs.deny` bypass with an invalid `request-target`
MEDIUM 5.3
CVE-2025-31125
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
UNKNOWN
CVE-2026-53632
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
HIGH 7.5
CVE-2026-53571
vite: `server.fs.deny` bypass on Windows alternate paths
UNKNOWN
CVE-2026-39364
Vite: `server.fs.deny` bypassed with queries
UNKNOWN
CVE-2026-39365
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
UNKNOWN
CVE-2025-62522
vite allows server.fs.deny bypass via backslash on Windows
UNKNOWN
CVE-2025-58752
Vite's `server.fs` settings were not applied to HTML files
UNKNOWN
CVE-2025-58751
Vite middleware may serve files starting with the same name with the public directory
UNKNOWN
CVE-2025-46565
Vite's server.fs.deny bypassed with /. for files under project root
MEDIUM 5.3
CVE-2025-30208
Vite bypasses server.fs.deny when using ?raw??
MEDIUM 6.5
CVE-2025-24010
Websites were able to send any requests to the development server and read the response in vite
MEDIUM 6.4
CVE-2024-45812
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
MEDIUM 5.3
CVE-2024-45811
Vite's `server.fs.deny` is bypassed when using `?import&raw`
MEDIUM 5.9
CVE-2024-31207
Vite's `server.fs.deny` did not deny requests for patterns with directories.
HIGH 7.5
CVE-2023-34092
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
MEDIUM 5.3
CVE-2025-31486
Vite allows server.fs.deny to be bypassed with .svg or relative paths
HIGH 7.5
CVE-2024-23331
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
HIGH 8.6
CVE-2022-35204
Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service
MEDIUM 6.1
CVE-2023-49293
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes