Vite's `server.fs.deny` did not deny requests for patterns with directories. (CVE-2024-31207)
Vite's development server option `server.fs.deny` did not properly deny requests for patterns that include directories, such as `/foo/**/*`. This affected applications that set a custom `server.fs.deny` with directory patterns and exposed the Vite dev server to the network. The issue was due to the use of picomatch with the `matchBase: true` option, which only matches basenames and not full paths, allowing unauthorized access to files under denied directories. This vulnerability is fixed in Vite versions 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10, and 2.9.18.
AI Analysis
Technical Summary
The Vite dev server's `server.fs.deny` configuration option uses picomatch with the `matchBase: true` setting, which only matches the basename of files rather than their full path. This behavior caused directory patterns (e.g., `/foo/**/*`) to not effectively deny access to files within those directories. Consequently, if an application sets a custom `server.fs.deny` including directory patterns and exposes the dev server to the network (via `--host` or `server.host`), unauthorized file access could occur. The issue also relates to the lack of the `{ dot: true }` option, which means dotfiles are not denied unless explicitly specified. The vulnerability is addressed in Vite versions 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10, and 2.9.18.
Potential Impact
Only applications that configure a custom `server.fs.deny` with directory patterns and expose the Vite development server to the network are affected. In such cases, unauthorized access to files within denied directories (including dotfiles if not explicitly denied) is possible, potentially exposing sensitive files such as `.git/config`. The CVSS score is 5.9 (medium severity), indicating a moderate impact with network attack vector, high attack complexity, no privileges required, and no user interaction needed. Confidentiality is impacted, but integrity and availability are not.
Mitigation Recommendations
A fix is available and users should upgrade to Vite versions 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10, or 2.9.18. Applications using custom `server.fs.deny` patterns with directories and exposing the dev server to the network should apply these updates promptly. No additional mitigation is required if the dev server is not exposed externally or if directory patterns are not used in `server.fs.deny`.
Vite's `server.fs.deny` did not deny requests for patterns with directories. (CVE-2024-31207)
Description
Vite's development server option `server.fs.deny` did not properly deny requests for patterns that include directories, such as `/foo/**/*`. This affected applications that set a custom `server.fs.deny` with directory patterns and exposed the Vite dev server to the network. The issue was due to the use of picomatch with the `matchBase: true` option, which only matches basenames and not full paths, allowing unauthorized access to files under denied directories. This vulnerability is fixed in Vite versions 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10, and 2.9.18.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Vite dev server's `server.fs.deny` configuration option uses picomatch with the `matchBase: true` setting, which only matches the basename of files rather than their full path. This behavior caused directory patterns (e.g., `/foo/**/*`) to not effectively deny access to files within those directories. Consequently, if an application sets a custom `server.fs.deny` including directory patterns and exposes the dev server to the network (via `--host` or `server.host`), unauthorized file access could occur. The issue also relates to the lack of the `{ dot: true }` option, which means dotfiles are not denied unless explicitly specified. The vulnerability is addressed in Vite versions 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10, and 2.9.18.
Potential Impact
Only applications that configure a custom `server.fs.deny` with directory patterns and expose the Vite development server to the network are affected. In such cases, unauthorized access to files within denied directories (including dotfiles if not explicitly denied) is possible, potentially exposing sensitive files such as `.git/config`. The CVSS score is 5.9 (medium severity), indicating a moderate impact with network attack vector, high attack complexity, no privileges required, and no user interaction needed. Confidentiality is impacted, but integrity and availability are not.
Mitigation Recommendations
A fix is available and users should upgrade to Vite versions 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10, or 2.9.18. Applications using custom `server.fs.deny` patterns with directories and exposing the dev server to the network should apply these updates promptly. No additional mitigation is required if the dev server is not exposed externally or if directory patterns are not used in `server.fs.deny`.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-vite-CVE-2024-31207
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6abb419cf7a7c54106cc387c
Added to database: 09/29/2026, 04:42:04 UTC
Last enriched: 09/29/2026, 04:55:16 UTC
Last updated: 09/29/2026, 18:11:12 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.