S4E just found a low-severity finding from dns any record query
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-31486

5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.
Description

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than build.assetsInlineLimit (default: 4kB) and when using Vite 6.0+. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 4.5.12, 5.4.17, 6.0.14, 6.1.4, and 6.2.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
vite
Updated Sep 28, 2026View on NVD →
S4E scanner

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →