PT-2026-49574 · Vite · Vite

·

CVE-2026-53571

·

Published

2026-06-01

·

Updated

2026-07-02

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vite versions prior to 8.0.16 Vite versions prior to 7.3.5 Vite versions prior to 6.4.3
Description On Windows, the development server fails to correctly normalize NTFS Alternate Data Streams (ADS) path forms and 8.3 short name compatibility paths before performing access checks. This allows the contents of sensitive files specified in server.fs.deny (such as .env, .env.*, and *.{crt,pem}) to be returned to the browser. For example, a request to /.env::$DATA?raw is treated as an allowed path, but Windows resolves it to the original file's default data stream. This issue affects applications that explicitly expose the dev server to the network, where the sensitive file resides in directories allowed by server.fs.allow and is located on an NTFS volume or a volume with 8.3 short name generation enabled.
Recommendations Update to version 8.0.16. Update to version 7.3.5. Update to version 6.4.3.

Exploit

Fix

Path traversal

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09524
CVE-2026-53571
GHSA-FX2H-PF6J-XCFF

Affected Products

Vite