{"id":"CVE-2023-34092","aliases":["GHSA-353f-5xf4-qw67"],"url":"https://o3.security/vulnerability/CVE-2023-34092","summary":"Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)","details":"The issue involves a security vulnerability in Vite where the server options can be bypassed using a double forward slash (`//`). This vulnerability poses a potential security risk as it can allow unauthorized access to sensitive directories and files.\n\n### Steps to Fix. **Update Vite**: Ensure that you are using the latest version of Vite. Security issues like this are often fixed in newer releases.\\n2. **Secure the server configuration**: In your `vite.config.js` file, review and update the server configuration options to restrict access to unauthorized requests or directories.\n\n### Impact\nOnly users explicitly exposing the Vite dev server to the network (using `--host` or the [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host)) are affected and only files in the immediate Vite project root folder could be exposed.\\n\\n### Patches\\nFixed in vite@**4.3.9**, vite@**4.2.3**, vite@**4.1.5**, vite@**4.0.5** and in the latest minors of the previous two majors, vite@**3.2.7** and vite@**2.9.16**.\n\n ### Details \nVite serves the application with under the root-path of the project while running on the dev mode. By default, Vite uses the server option fs.deny to protect sensitive files. But using a simple double forward-slash, we can bypass this restriction. \\n\\n### PoC\\n1. Create a new latest project of Vite using any package manager. (here I'm using react and vue templates and pnpm for testing)\\n2. Serve the application on dev mode using `pnpm run dev`.\\n3. Directly access the file via url using double forward-slash (`//`) (e.g: `//.env`, `//.env.local`)\\n4. The server option `fs.deny` was successfully bypassed.\n\nProof Images: ![proof-1](https://user-images.githubusercontent.com/30733517/241105344-6ecbc7f6-57b7-45c7-856a-6421a577dda1.png)\\n![proof-2](https://user-images.githubusercontent.com/30733517/241105349-ab9561e7-8aff-4f29-97f9-b784e673c122.png)","published":"2023-06-01T16:29:51.428Z","modified":"2026-08-12T03:51:34.678374898Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.03152,"percentile":0.86718,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"vite","fixedVersion":"2.9.16"},{"ecosystem":"npm","name":"vite","fixedVersion":"3.2.7"},{"ecosystem":"npm","name":"vite","fixedVersion":"4.0.5"},{"ecosystem":"npm","name":"vite","fixedVersion":"4.1.5"},{"ecosystem":"npm","name":"vite","fixedVersion":"4.2.3"},{"ecosystem":"npm","name":"vite","fixedVersion":"4.3.9"}],"fix":{"url":"https://github.com/vitejs/vite/commit/813ddd6155c3d54801e264ba832d8347f6f66b32","label":"vitejs/vite@813ddd6"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34092.json"},{"type":"ADVISORY","url":"https://github.com/vitejs/vite/security/advisories/GHSA-353f-5xf4-qw67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34092"},{"type":"FIX","url":"https://github.com/vitejs/vite/commit/813ddd6155c3d54801e264ba832d8347f6f66b32"},{"type":"FIX","url":"https://github.com/vitejs/vite/pull/13348"},{"type":"PACKAGE","url":"https://github.com/vitejs/vite"},{"type":"WEB","url":"https://security.snyk.io/package/npm/vite/3.2.0-beta.4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.678374898Z"}}