CVE-2026-53571: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vitejs vite
Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw are treated as allowed paths, while Windows resolves them to the original file's default data stream. Similar to that, Windows allows accessing a file using a different name with the 8.3 short name compatibility feature. Vite did not reject accessing files via them. This vulnerability is fixed in 8.0.16, 7.3.5, and 6.4.3.
AI Analysis
Technical Summary
CVE-2026-53571 describes a path traversal vulnerability in vitejs vite's development server on Windows platforms. The server attempts to restrict access to sensitive files via server.fs.deny, blocking direct access to files like .env and certificate files. However, on Windows, the deny logic fails to normalize NTFS Alternate Data Stream (ADS) path forms and 8.3 short name aliases before applying access checks. This flaw permits attackers to bypass restrictions by requesting files using ADS syntax (e.g., /.env::$DATA?raw) or 8.3 short names, resulting in unauthorized file content disclosure. The vulnerability affects vite versions >=6.4.0 <6.4.3, >=7.0.0 <7.3.5, and >=8.0.0 <8.0.16 and is resolved in versions 6.4.3, 7.3.5, and 8.0.16.
Potential Impact
An attacker can bypass file access restrictions on the vite development server running on Windows by exploiting improper normalization of NTFS ADS paths and 8.3 short names. This leads to unauthorized disclosure of sensitive files such as environment configuration files (.env) and certificate files (.crt, .pem). The vulnerability has a high severity with a CVSS 4.0 score of 8.2, indicating a significant risk of information exposure without requiring privileges or user interaction.
Mitigation Recommendations
This vulnerability is fixed in vite versions 8.0.16, 7.3.5, and 6.4.3. Users should upgrade to these or later versions to remediate the issue. No other mitigation or temporary workaround is indicated. Patch status is confirmed by the vendor's versioning and CVE description.
CVE-2026-53571: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vitejs vite
Description
Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw are treated as allowed paths, while Windows resolves them to the original file's default data stream. Similar to that, Windows allows accessing a file using a different name with the 8.3 short name compatibility feature. Vite did not reject accessing files via them. This vulnerability is fixed in 8.0.16, 7.3.5, and 6.4.3.
CVSS v4.0
Score 8.2high
Affected software
pkg:npm/vitejs/viteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-53571 describes a path traversal vulnerability in vitejs vite's development server on Windows platforms. The server attempts to restrict access to sensitive files via server.fs.deny, blocking direct access to files like .env and certificate files. However, on Windows, the deny logic fails to normalize NTFS Alternate Data Stream (ADS) path forms and 8.3 short name aliases before applying access checks. This flaw permits attackers to bypass restrictions by requesting files using ADS syntax (e.g., /.env::$DATA?raw) or 8.3 short names, resulting in unauthorized file content disclosure. The vulnerability affects vite versions >=6.4.0 <6.4.3, >=7.0.0 <7.3.5, and >=8.0.0 <8.0.16 and is resolved in versions 6.4.3, 7.3.5, and 8.0.16.
Potential Impact
An attacker can bypass file access restrictions on the vite development server running on Windows by exploiting improper normalization of NTFS ADS paths and 8.3 short names. This leads to unauthorized disclosure of sensitive files such as environment configuration files (.env) and certificate files (.crt, .pem). The vulnerability has a high severity with a CVSS 4.0 score of 8.2, indicating a significant risk of information exposure without requiring privileges or user interaction.
Mitigation Recommendations
This vulnerability is fixed in vite versions 8.0.16, 7.3.5, and 6.4.3. Users should upgrade to these or later versions to remediate the issue. No other mitigation or temporary workaround is indicated. Patch status is confirmed by the vendor's versioning and CVE description.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-09T19:11:53.483Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a39735beed863c81e396243
Added to database: 06/22/2026, 17:39:39 UTC
Last enriched: 07/16/2026, 10:51:59 UTC
Last updated: 08/06/2026, 22:46:12 UTC
Views: 125
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.