Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem (CVE-2024-23331)
The Vite development server option `server.fs.deny` intended to block access to specified files can be bypassed on case-insensitive filesystems such as Windows by using case-augmented filenames. This allows unauthorized access to files that should be denied, including sensitive configuration and secret files. The issue arises because the underlying glob matching is case-sensitive while the filesystem is not, enabling attackers to circumvent the deny list by altering filename casing. This vulnerability affects Vite versions from 2.7.0 up to but not including 5.0.12.
AI Analysis
Technical Summary
CVE-2024-23331 describes a bypass of the Vite dev server's `server.fs.deny` option on case-insensitive filesystems. The deny list uses `picomatch` for glob pattern matching, which defaults to case-sensitive matching, but the file server itself does not discriminate by case. As a result, requests using filenames with altered casing can access files that should be blocked. This vulnerability is particularly relevant for Windows hosts. It was fixed in vite versions 5.0.12, 4.5.2, 3.2.8, and 2.9.17. A proof of concept demonstrates accessing secret files by changing the case of filenames in HTTP requests.
Potential Impact
Attackers can bypass the file access restrictions configured via `server.fs.deny` on Vite dev servers running on case-insensitive filesystems, such as Windows. This leads to unauthorized disclosure of files intended to be protected, including environment files, certificates, and custom secret files. The vulnerability does not affect case-sensitive filesystems. The CVSS score is 7.5 (high), indicating significant confidentiality impact without integrity or availability impact.
Mitigation Recommendations
A fix is available and users should upgrade to vite versions 5.0.12, 4.5.2, 3.2.8, or 2.9.17 or later. Applying these official patches will prevent the bypass of the `server.fs.deny` option on case-insensitive filesystems. No additional mitigation steps are indicated by the vendor advisory.
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem (CVE-2024-23331)
Description
The Vite development server option `server.fs.deny` intended to block access to specified files can be bypassed on case-insensitive filesystems such as Windows by using case-augmented filenames. This allows unauthorized access to files that should be denied, including sensitive configuration and secret files. The issue arises because the underlying glob matching is case-sensitive while the filesystem is not, enabling attackers to circumvent the deny list by altering filename casing. This vulnerability affects Vite versions from 2.7.0 up to but not including 5.0.12.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-23331 describes a bypass of the Vite dev server's `server.fs.deny` option on case-insensitive filesystems. The deny list uses `picomatch` for glob pattern matching, which defaults to case-sensitive matching, but the file server itself does not discriminate by case. As a result, requests using filenames with altered casing can access files that should be blocked. This vulnerability is particularly relevant for Windows hosts. It was fixed in vite versions 5.0.12, 4.5.2, 3.2.8, and 2.9.17. A proof of concept demonstrates accessing secret files by changing the case of filenames in HTTP requests.
Potential Impact
Attackers can bypass the file access restrictions configured via `server.fs.deny` on Vite dev servers running on case-insensitive filesystems, such as Windows. This leads to unauthorized disclosure of files intended to be protected, including environment files, certificates, and custom secret files. The vulnerability does not affect case-sensitive filesystems. The CVSS score is 7.5 (high), indicating significant confidentiality impact without integrity or availability impact.
Mitigation Recommendations
A fix is available and users should upgrade to vite versions 5.0.12, 4.5.2, 3.2.8, or 2.9.17 or later. Applying these official patches will prevent the bypass of the `server.fs.deny` option on case-insensitive filesystems. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-vite-CVE-2024-23331
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6abb419cf7a7c54106cc387d
Added to database: 09/29/2026, 04:42:04 UTC
Last enriched: 09/29/2026, 04:55:21 UTC
Last updated: 09/29/2026, 18:11:12 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.