type: cve ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [cve] ยท confidence: medium ยท severity: medium ยท affected_sectors: [global] ยท au_impact: false
NVD description: Vite exposes the content of non-allowed files using ?inline&import or ?raw?import. Only applications that explicitly expose the Vite dev server to the network, using --host or server.host, are affected.
Most observed activity originated from the United States, Belgium and the Netherlands, with attackers using Google Cloud IP ranges for evasion, and the most active addresses were also leveraging older access-control flaws in the same project (CVE-2025-30208, CVE-2025-31125 and CVE-2024-45811).
| Attribute | Detail |
|---|---|
| CVE | CVE-2025-31125 |
| CVSS | 5.3 (Medium) |
| Vendor / product | Vite (frontend tooling framework for JavaScript) |
| Reported | 2026-09-16 |