#VU125307 Improper access control in Vite - CVE-2025-32395
Published: April 10, 2025 / Updated: April 8, 2026
Vite
Vite
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the server.fs.deny check when handling an invalid request-target containing a # character. A remote attacker can send a specially crafted request to disclose sensitive information.
Only instances that explicitly expose the dev server to the network and run on Node or Bun are vulnerable. User interaction is required.