Path equivalence issue in Vite - CVE-2023-34092

 

Path equivalence issue in Vite - CVE-2023-34092

Published: June 1, 2023 / Updated: April 8, 2026


Vulnerability identifier: #VU125306
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34092
CWE-ID: CWE-50
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the Vite dev server file access restriction handling when processing requests containing a double forward-slash path. A remote attacker can send a specially crafted request to disclose sensitive information.

Only instances explicitly exposed to the network are affected, and only files in the immediate Vite project root folder could be exposed.


Affected software

Vite

How to mitigate CVE-2023-34092

Install security update from vendor's website.

Vite - addressed in versions 3.0.0, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.3.9

External References

Related Security Bulletins