Vite bypasses server.fs.deny when using ?raw?? (CVE-2025-30208)
A vulnerability in Vite allows bypassing the server.fs.deny restriction when using the ?raw?? or ?import&raw?? query parameters. This enables an attacker to retrieve the contents of arbitrary files outside the allowed serving list. The issue affects Vite dev servers explicitly exposed to the network via the --host option or server.host configuration. The vulnerability arises because trailing question marks are stripped inconsistently, allowing the bypass of query string checks.
AI Analysis
Technical Summary
CVE-2025-30208 is a vulnerability in Vite versions >=2.5.1 and <6.2.3 where the server.fs.deny restriction can be bypassed by appending ?raw?? or ?import&raw?? to file URLs. This bypass returns the contents of arbitrary files to the browser, circumventing the intended file access restrictions. The root cause is inconsistent handling of trailing question marks in query strings, which are removed in some processing steps but not accounted for in regex-based access controls. The vulnerability only affects Vite dev servers exposed to the network via the --host option or server.host config.
Potential Impact
An attacker able to access a Vite dev server exposed to the network can retrieve arbitrary file contents from the server filesystem, potentially exposing sensitive information. This does not affect default local-only servers. The vulnerability has a CVSS 3.1 score of 5.3 (medium severity), indicating a moderate impact with network attack vector, high complexity, no privileges required, user interaction required, and confidentiality impact only.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade Vite to version 6.2.3 or later to remediate this issue. Until patched, avoid exposing the Vite dev server to the network using the --host option or server.host configuration to prevent exploitation.
Vite bypasses server.fs.deny when using ?raw?? (CVE-2025-30208)
Description
A vulnerability in Vite allows bypassing the server.fs.deny restriction when using the ?raw?? or ?import&raw?? query parameters. This enables an attacker to retrieve the contents of arbitrary files outside the allowed serving list. The issue affects Vite dev servers explicitly exposed to the network via the --host option or server.host configuration. The vulnerability arises because trailing question marks are stripped inconsistently, allowing the bypass of query string checks.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-30208 is a vulnerability in Vite versions >=2.5.1 and <6.2.3 where the server.fs.deny restriction can be bypassed by appending ?raw?? or ?import&raw?? to file URLs. This bypass returns the contents of arbitrary files to the browser, circumventing the intended file access restrictions. The root cause is inconsistent handling of trailing question marks in query strings, which are removed in some processing steps but not accounted for in regex-based access controls. The vulnerability only affects Vite dev servers exposed to the network via the --host option or server.host config.
Potential Impact
An attacker able to access a Vite dev server exposed to the network can retrieve arbitrary file contents from the server filesystem, potentially exposing sensitive information. This does not affect default local-only servers. The vulnerability has a CVSS 3.1 score of 5.3 (medium severity), indicating a moderate impact with network attack vector, high complexity, no privileges required, user interaction required, and confidentiality impact only.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade Vite to version 6.2.3 or later to remediate this issue. Until patched, avoid exposing the Vite dev server to the network using the --host option or server.host configuration to prevent exploitation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-vite-CVE-2025-30208
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6abb419cf7a7c54106cc3877
Added to database: 09/29/2026, 04:42:04 UTC
Last enriched: 09/29/2026, 04:54:33 UTC
Last updated: 09/29/2026, 18:11:14 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.