type: cve ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [cve] ยท confidence: medium ยท severity: medium ยท affected_sectors: [global] ยท au_impact: false
NVD description: The contents of arbitrary files can be returned to the browser: @fs denies access outside the Vite serving allow list, but adding ?import&raw to the request bypasses that denial. Affects versions before 6.2.0, 5.4.15, 4.5.10 and their peers.
Most observed activity originated from the United States, Belgium and the Netherlands, with attackers using Google Cloud IP ranges for evasion, and the most active addresses were also leveraging older access-control flaws in the same project (CVE-2025-30208, CVE-2025-31125 and CVE-2024-45811).
| Attribute | Detail |
|---|---|
| CVE | CVE-2024-45811 |
| CVSS | 4.8 (Medium) |
| Vendor / product | Vite (frontend build tooling for JavaScript) |
| Reported | 2026-09-16 |