Security Advisories for vite in npm
Moderate
2 months ago
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
npm
vite-plus, vite, launch-editor
Low
11 months ago
Vite middleware may serve files starting with the same name with the public directory
npm
vite
Moderate
over 1 year ago
Vite's server.fs.deny bypassed with /. for files under project root
npm
vite
Moderate
over 1 year ago
Vite has an `server.fs.deny` bypass with an invalid `request-target`
npm
vite
Moderate
over 1 year ago
Vite allows server.fs.deny to be bypassed with .svg or relative paths
npm
vite
Moderate
over 1 year ago
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
npm
vite
Moderate
over 1 year ago
Websites were able to send any requests to the development server and read the response in vite
npm
vite
Moderate
almost 2 years ago
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
npm
vite
Moderate
over 2 years ago
Vite's `server.fs.deny` did not deny requests for patterns with directories.
npm
vite
High
over 2 years ago
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
npm
vite
Moderate
over 2 years ago
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
npm
vite
High
about 3 years ago
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
npm
vite
High
almost 4 years ago
Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service
npm
vite