PT-2025-51776 · Vitejs · @Vitejs/Plugin-Rs

Published

2025-12-16

·

Updated

2025-12-17

·

CVE-2025-68155

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions @vitejs/plugin-rs versions prior to 0.5.8
Description The @vitejs/plugin-rs software, which provides React Server Components (RSC) support for Vite, has an issue where the / vite rsc findSourceMapURL API endpoint allows unauthenticated arbitrary file read during development mode. An attacker can potentially read any file accessible to the Node.js process by sending a specially crafted HTTP request. The request includes a file:// URL within the filename query parameter.
Recommendations Update to version 0.5.8 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-68155
GHSA-G239-Q96Q-X4QM

Affected Products

@Vitejs/Plugin-Rs