CVE-2025-31125: Vite Vitejs Improper Access Control Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-01-22. EPSS: 65.2% chance of exploitation in the next 30 days.

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.

Affected products

  • Vitejs Vite: before 4.5.11 (fixed in 4.5.11); from 5.0.0, before 5.4.16 (fixed in 5.4.16); from 6.0.0, before 6.0.13 (fixed in 6.0.13); from 6.1.0, before 6.1.3 (fixed in 6.1.3); from 6.2.0, before 6.2.4 (fixed in 6.2.4)

Published 2025-03-31. Last modified 2026-06-17.