← Back to CVE List
Vulnerability Analysis
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

CVE-2025-31125

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.

CISA KEV Nuclei Template
CVSS Base Score
5.3
MEDIUM
Exploitability:1.7
Impact Score:3.6
Temporal Score:-
EPSS:62.10%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2026-01-22
Ransomware Use
Unknown
KEV Due Date
2026-02-12
VulnCheck In-the-Wild
No
Nuclei Template
YES
EPSS Score
62.100%
EPSS Percentile
99.1th pct
GitHub Severity
MODERATE
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD