PT-2026-49574 · Vite · Vite
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vite versions prior to 8.0.16
Vite versions prior to 7.3.5
Vite versions prior to 6.4.3
Description
On Windows, the development server fails to correctly normalize NTFS Alternate Data Streams (ADS) path forms and 8.3 short name compatibility paths before performing access checks. This allows the contents of sensitive files specified in
server.fs.deny (such as .env, .env.*, and *.{crt,pem}) to be returned to the browser. For example, a request to /.env::$DATA?raw is treated as an allowed path, but Windows resolves it to the original file's default data stream. This issue affects applications that explicitly expose the dev server to the network, where the sensitive file resides in directories allowed by server.fs.allow and is located on an NTFS volume or a volume with 8.3 short name generation enabled.Recommendations
Update to version 8.0.16.
Update to version 7.3.5.
Update to version 6.4.3.
Exploit
Fix
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vite