Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 21, 2025

This PR contains the following updates:

Package Change Age Confidence
vite (source) 6.3.6 -> 6.4.1 age confidence

GitHub Vulnerability Alerts

CVE-2025-62522

Summary

Files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows.

Impact

Only apps that match the following conditions are affected:

  • explicitly exposes the Vite dev server to the network (using --host or server.host config option)
  • running the dev server on Windows

Details

server.fs.deny can contain patterns matching against files (by default it includes .env, .env.*, *.{crt,pem} as such patterns). These patterns were able to bypass by using a back slash(\). The root cause is that fs.readFile('/foo.png/') loads /foo.png.

PoC

npm create vite@latest cd vite-project/ cat "secret" > .env npm install npm run dev curl --request-target /.env\ http://localhost:5173
image

Release Notes

vitejs/vite (vite)

v6.4.1

Compare Source

Please refer to CHANGELOG.md for details.

v6.4.0

Compare Source

Please refer to CHANGELOG.md for details.

v6.3.7

Compare Source

Please refer to CHANGELOG.md for details.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link

github-actions bot commented Oct 21, 2025

COMPARE TO master

Total Size Diff ⚠️ 📈 +27.08 KB

Diff by File
Name Diff
pnpm-lock.yaml ⚠️ 📈 +27.08 KB
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from a5a2a1e to 787a510 Compare October 21, 2025 15:17
@github-actions github-actions bot added size/xs and removed size/xs labels Oct 21, 2025
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 787a510 to 86d35e7 Compare October 28, 2025 07:12
@github-actions github-actions bot added size/xs and removed size/xs labels Oct 28, 2025
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 86d35e7 to 2373dda Compare October 31, 2025 04:32
@github-actions github-actions bot added size/xs and removed size/xs labels Oct 31, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 participant