CVE-2025-31125HIGH 7.5CISA KEVEPSS p99.0%
CVE-2025-31125Vite Vitejs Improper Access Control Vulnerability
Vite / Vitejs
Description
Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.
Scoring
| CVSS 3.1 | 7.5 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 59.59% probability of exploitation · percentile 99.0% · 2026-06-18T12:00:27Z |
| Published | 2025-03-31 |
| Last modified | 2026-01-23 |
CISA KEV entry
Added to KEV: 2026-01-22
Underlying weaknesses· 2
References
- https://github.com/vitejs/vite/commit/59673137c45ac2bcfad1170d954347c1a17ab949
- https://github.com/vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8
- https://github.com/vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31125
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 0% | live |
| Weakness | Improper Access Controlcwe-284 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Vite Vitejs Improper Access Control Vulnerabilitykev-cve-2025-31125 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.