GHSA-93m4-6634-74q7 — vite
Fix: vitejs/vite@f479cc5GHSA-93m4-6634-74q7 is a Path Traversal vulnerability in vite. A fix is available for vite — see the affected versions and patch details below.
vite allows server.fs.deny bypass via backslash on Windows
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
Exploitation and automatability from CISA’s SSVC triage for GHSA-93m4-6634-74q7.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
vitenpmDescription
Summary
Files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows.
Impact
Only apps that match the following conditions are affected:
- explicitly exposes the Vite dev server to the network (using --host or
server.hostconfig option) - running the dev server on Windows
Details
server.fs.deny can contain patterns matching against files (by default it includes .env, .env.*, *.{crt,pem} as such patterns). These patterns were able to bypass by using a back slash(\). The root cause is that fs.readFile('/foo.png/') loads /foo.png.
PoC
npm create vite@latest
cd vite-project/
cat "secret" > .env
npm install
npm run dev
curl --request-target /.env\ http://localhost:5173
<img width="1593" height="616" alt="image" src="https://github.com/user-attachments/assets/36212f4e-1d3c-4686-b16f-16b35ca9e175" />Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | vite | ≥ 7.1.0&&< 7.1.11 | 7.1.11npm install vite@7.1.11 |
| 📦npm | vite | ≥ 7.0.0&&< 7.0.8 | 7.0.8npm install vite@7.0.8 |
| 📦npm | vite | ≥ 6.0.0&&< 6.4.1 | 6.4.1npm install vite@6.4.1 |
| 📦npm | vite | ≥ 2.9.18&&< 5.4.21 | 5.4.21npm install vite@5.4.21 |
| 📦npm | vite | ≥ 3.2.9&&< 5.4.21 | 5.4.21npm install vite@5.4.21 |
| 📦npm | vite | ≥ 4.5.3&&< 5.4.21 | 5.4.21npm install vite@5.4.21 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for vite, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update vite to 7.1.11 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-93m4-6634-74q7 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-93m4-6634-74q7 can be triaged on real exposure rather than presence alone.
Tailored to GHSA-93m4-6634-74q7. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
How to detect GHSA-93m4-6634-74q7
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id ghsa-93m4-6634-74q7 -u https://target- Template
- Vite - Information Disclosure
- Severity
- medium
- Impact
- Remote attackers can access files denied by server.fs.deny, leading to sensitive information disclosure.
- Remediation
- Update to versions 5.4.21, 6.4.1, 7.0.8, or 7.1.11 or later.
Template by ProjectDiscovery nuclei-templates (DhiyaneshDK), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is GHSA-93m4-6634-74q7 in your dependencies?
O3 Security finds GHSA-93m4-6634-74q7 across npm dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.