Vulnerability record · CVE-2025-30208 · published 24 March 2025
CVE-2025-30208: Vite dev server @fs allow-list bypass exposes arbitrary files
Vitejs · Vite
Vite versions before 6.2.3, 6.1.2, 6.0.12, 5.4.15 and 4.5.10 mishandle trailing separators in query string regexes, so appending ?raw?? or ?import&raw?? to a URL bypasses the @fs allow-list and returns the contents of arbitrary files. Only dev servers explicitly exposed to the network via --host or server.host are affected, but those instances leak source and any readable file to unauthenticated clients.
Description
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network file disclosure with a high EPSS score and public exploit reference, though limited to dev servers explicitly exposed to the network.
What it is
Vite versions before 6.2.3, 6.1.2, 6.0.12, 5.4.15 and 4.5.10 mishandle trailing separators in query string regexes, so appending ?raw?? or ?import&raw?? to a URL bypasses the @fs allow-list and returns the contents of arbitrary files. Only dev servers explicitly exposed to the network via --host or server.host are affected, but those instances leak source and any readable file to unauthenticated clients.
Impact
An attacker reads arbitrary files from the host filesystem through the dev server, including source code, configuration and potentially credentials or keys, with no write or code execution shown by the record.
Attack surface
Reached over the network via HTTP requests to a Vite dev server bound to a non-local interface; the CVSS vector shows no privileges and no user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.74969 (99.5th percentile) and a reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Vite to 6.2.3, 6.1.2, 6.0.12, 5.4.15 or 4.5.10 (or later) immediately.
- Stop exposing the Vite dev server to untrusted networks; remove --host and server.host bindings or restrict them to localhost.
- If remote access is required, place the dev server behind authentication and network allow-lists rather than leaving it open.
- Audit hosts that ran exposed dev servers for file disclosure and rotate any secrets readable from those filesystems.
Detection
- Search HTTP access logs for requests containing ?raw?? or ?import&raw?? and for @fs paths outside the project root.
- Alert on Vite dev server processes listening on non-loopback addresses.
- Monitor for anomalous reads of sensitive files (env files, SSH keys, config) by the Node process running Vite.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-30208 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-30208), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.