CVE-2025-30208
CVSS 5.3 MEDIUM: vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. EPSS 75% (99th percentile).
Vulnerabilities & Exploits · Credential Theft
A mass-scanning campaign is targeting exposed Vite development servers to steal AWS and Azure credentials, and the flaw behind it is CVE-2025-30208 in Vite versions before 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. BleepingComputer says the activity is hitting internet-reachable dev servers, not just local setups.
The bug lets the dev server expose files from the developer’s machine over HTTP, so someone who can reach it can read local config files that already contain cloud keys. That means the attacker is stealing standing credentials rather than forcing their way into AWS or Azure, and the cloud access can outlast the vulnerable server itself.
For teams that expose preview or development tooling outside a trusted network, the exposure is broader than the web app alone: a single reachable box can become a cloud foothold. If those local secrets are reused for CI/CD or data access, the blast radius extends to the systems those credentials already unlock.
1 source · 11h ago
CVSS 5.3 MEDIUM: vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. EPSS 75% (99th percentile).
BleepingComputer
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.
originalPart of the PlainSec briefing for 2026-09-14
Every edition of this story: Vite Dev Servers Are Leaking Cloud Credentials