CVE-2025-30208
CVSS 5.3 MEDIUM: vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. EPSS 75% (99º percentile).
Vulnerabilità · 180 giorni fa
Gli aggressori stanno attivamente sondando i server di sviluppo Vite esposti su internet utilizzando CVE-2025-30208. Inviano richieste con il prefisso '/@fs/' e il suffisso '?raw??' per bypassare la directory allowlist di Vite e scaricare file arbitrari come /etc/environment e .aws/credentials. I server di sviluppo Vite tipicamente ascoltano sulla porta 5173 e non dovrebbero essere esposti su internet, ma gli aggressori scansionano le porte web comuni presumendo l'esposizione.
CVSS 5.3 MEDIUM: vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. EPSS 75% (99º percentile).
1 fonte che coprono questa storia
Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), Author: Johannes Ullrich
Part of the PlainSec briefing for 2026-04-03