#VU125308 Path traversal in Vite - CVE-2025-58751
Published: April 8, 2026
Vite
Vite
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in servePublicMiddleware / viteServePublicMiddleware when handling crafted path requests to public files. A remote attacker can send a specially crafted request using traversal sequences to disclose sensitive information.
Only applications that expose the Vite dev server to the network, use the public directory feature, and have a symbolic link anywhere inside the public directory are affected. User interaction is required.