Relative Path Traversal in Vite - CVE-2025-58752

 

Relative Path Traversal in Vite - CVE-2025-58752

Published: April 8, 2026


Vulnerability identifier: #VU125309
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58752
CWE-ID: CWE-23
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to relative path traversal in HTML file handling middleware when processing requests for HTML files. A remote attacker can send a specially crafted request to disclose sensitive information.

Only applications that explicitly expose the Vite dev server to the network and use appType 'spa' or 'mpa' are affected. The issue also affects the preview server.


Affected software

Vite

How to mitigate CVE-2025-58752

Install security update from vendor's website.

Vite - addressed in versions 5.4.20, 6.3.6, 7.0.7, 7.1.5

External References

Related Security Bulletins