Vite Dev Server - Information Exposure
CVE-2023-34092
Verified
Description
Vite dev server could allow reading files from the Vite project root by bypassing server.fs.deny with double forward-slash paths (//). This affects exposed dev servers only.
Severity
High
CVSS Score
7.5
Exploit Probability
3%
Published Date
March 26, 2026
Template Author
ritikchaddha
CVE-2023-34092.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2023-34092
CWE ID:
cwe-50
Remediation Steps
Update to Vite version 4.3.9, 4.2.3, 4.1.5, 4.0.5, 3.2.7, or 2.9.16 or later.