Information disclosure in Vite - CVE-2025-31125
Published: April 2, 2025 / Updated: January 22, 2026
Vulnerability identifier: #VU106382
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31125
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the contents of arbitrary files can be returned to the browser. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Vite
Guardium Data Security Center (GDSC)
IBM Concert Software
Guardium Data Security Center (GDSC)
IBM Concert Software
How to mitigate CVE-2025-31125
Install updates from vendor's website.
Vite - addressed in versions 4.5.11, 5.4.16, 6.0.13, 6.1.3, 6.2.4
IBM Concert Software - update to 2.0.0
Guardium Data Security Center (GDSC) - update to 3.8.1
IBM Concert Software - update to 2.0.0
Guardium Data Security Center (GDSC) - update to 3.8.1