A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2025-31125

Vite Vitejs Improper Access Control Vulnerability

Published
2026-01-22
Modified
2026-07-31
Sources
cisa-kev

Summary

Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.