#VU125301 Improper access control in Vite - CVE-2025-24010
Published: January 20, 2025 / Updated: April 8, 2026
Vite
Vite
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the development server when handling cross-origin requests. A remote attacker can send a specially crafted request from a malicious website to disclose sensitive information.
User interaction is required to visit a malicious website.