You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
The contents of files in the project root that are denied by a file matching pattern can be returned to the browser.
Impact
Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.
Only files that are under project root and are denied by a file matching pattern can be bypassed.
Examples of file matching patterns: .env, .env.*, *.{crt,pem}, **/.env
Examples of other patterns: **/.git/**, .git/**, .git/**/*
Details
server.fs.deny can contain patterns matching against files (by default it includes .env, .env.*, *.{crt,pem} as such patterns).
These patterns were able to bypass for files under root by using a combination of slash and dot (/.).
PoC
npm create vite@latest
cd vite-project/
cat "secret" > .env
npm install
npm run dev
curl --request-target /.env/. http://localhost:5173
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
This PR includes no changesets
When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.3 [security]
chore(deps): update dependency vite to v6.2.3 [security] - autoclosed
Mar 25, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.3 [security] - autoclosed
chore(deps): update dependency vite to v6.2.3 [security]
Mar 31, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.3 [security]
chore(deps): update dependency vite to v6.2.4 [security]
Mar 31, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.4 [security]
chore(deps): update dependency vite to v6.2.5 [security]
Apr 4, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.5 [security]
chore(deps): update dependency vite to v6.2.6 [security]
Apr 11, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.6 [security]
chore(deps): update dependency vite to v6.2.6 [security] - autoclosed
Apr 25, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.6 [security] - autoclosed
chore(deps): update dependency vite to v6.2.6 [security]
Apr 30, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.6 [security]
chore(deps): update dependency vite to v6.2.7 [security]
Apr 30, 2025
renovatebot
changed the title
chore(deps): update dependency vite to v6.2.7 [security]
chore(deps): update dependency vite to v6.2.7 [security] - autoclosed
May 3, 2025
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.2.6
->6.2.7
GitHub Vulnerability Alerts
CVE-2025-46565
Summary
The contents of files in the project
root
that are denied by a file matching pattern can be returned to the browser.Impact
Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.
Only files that are under project
root
and are denied by a file matching pattern can be bypassed..env
,.env.*
,*.{crt,pem}
,**/.env
**/.git/**
,.git/**
,.git/**/*
Details
server.fs.deny
can contain patterns matching against files (by default it includes.env
,.env.*
,*.{crt,pem}
as such patterns).These patterns were able to bypass for files under
root
by using a combination of slash and dot (/.
).PoC
Release Notes
vitejs/vite (vite)
v6.2.7
Compare Source
Please refer to CHANGELOG.md for details.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.