Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [cve] ยท confidence: medium ยท severity: medium ยท affected_sectors: [global] ยท au_impact: false

NVD description: @fs denies access to files outside the Vite serving allow list, but appending ?raw?? or ?import&raw? to a request bypasses it. Affects versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15 and 4.5.10.

Most observed activity originated from the United States, Belgium and the Netherlands, with attackers using Google Cloud IP ranges for evasion, and the most active addresses were also leveraging older access-control flaws in the same project (CVE-2025-30208, CVE-2025-31125 and CVE-2024-45811).

Attribute Detail
CVE CVE-2025-30208
CVSS 5.3 (Medium)
Vendor / product Vite (frontend development tooling)
Reported 2026-09-16