CVE-2025-68155: Vitejs Vite-Plugin-React
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.5.8 fixes the issue.
Affected products
- Vitejs Vite-Plugin-React: before 0.5.8 (fixed in 0.5.8)
Published 2025-12-16. Last modified 2026-06-17.