CVE-2025-31125Vite Vitejs Improper Access Control Vulnerability

PUBLISHEDvulnerability record
2026-01-22 · last modified January 23, 2026

Metadata

CVE ID:
CVE-2025-31125
项目:
Vite
产品:
Vitejs
添加日期:
2026-01-22
到期日:
2026-02-12
最后更新:
January 23, 2026

漏洞名称

Vite Vitejs Improper Access Control Vulnerability

描述

Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.

已知用于勒索软件活动吗?

勒索软件状态:
Unknown

采集行动

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

其他说明

相关新闻文章

相关 CWE