CVE-2024-31207: Vitejs Vite
Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.
Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10 and 2.9.18.
Affected products
- Vitejs Vite: from 2.7.0, up to and including 2.9.17; from 3.0.0, up to and including 3.2.8; from 4.0.0, up to and including 4.5.2; from 5.0.0, up to and including 5.0.12; from 5.1.0, up to and including 5.1.6; from 5.2.0, up to and including 5.2.5
Published 2024-04-04. Last modified 2026-06-17.