#VU125303 Improper access control in Vite - CVE-2024-45811
Published: September 17, 2024 / Updated: April 8, 2026
Vite
Vite
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the @fs file serving mechanism when handling requests with the ?import&raw query parameter. A remote attacker can send a specially crafted request to disclose sensitive information.
User interaction is required.