Vite - Path Traversal
CVE-2025-32395
Verified
Description
Vite versions prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13 contain a file exposure vulnerability caused by improper handling of request URLs with '#' in the dev server running on Node or Bun, letting attackers access arbitrary files, exploit requires the server to be exposed to the network and running on Node or Bun.
Severity
Medium
CVSS Score
6
Exploit Probability
2%
Published Date
May 2, 2026
Template Author
chrisjr404
CVE-2025-32395.yaml
6.0Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2025-32395
CWE ID:
cwe-200
Remediation Steps
Update to version 6.2.6, 6.1.5, 6.0.15, 5.4.18, or 4.5.13 or later.