S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 6, 2026

CVE-2025-62522 Scanner

CVE-2025-62522 Scanner - Information Disclosure vulnerability in Vite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-62522
6.0
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.

Attack Vector
Network
Privileges Req.
None
User Interaction
P
Affected
viteby vitejs
>= 7.1.0, < 7.1.11
Updated Aug 22, 2026View on NVD →
Detail

Vite is a modern frontend tooling framework used primarily in JavaScript development. It is utilized by developers worldwide for creating responsive and optimized web applications. By offering rapid development server and efficient build processes, Vite enhances developers' productivity. The framework is commonly employed in dynamic websites and single-page applications. Companies leveraging JavaScript technologies often use Vite for its advanced bundling capabilities. Vite precisely caters to frontend development needs with its rich plugin ecosystem and enhanced performance features.

Information Disclosure is a vulnerability where sensitive information is unintentionally revealed to unauthorized users. In the Vite framework, certain server configurations could lead to exposing restricted files. This occurs especially when the dev server is improperly configured on Windows environments, where files meant to be hidden are sent if a URL ends with a specific character. Attackers can exploit this to obtain crucial details about the application's environment. Addressing this flaw is crucial as it may reveal sensitive configurations and data.

This vulnerability is technically tied to how the Vite dev server processes requests on Windows. Specifically, files denied by the server.fs.deny setting were inadvertently served if the request's URL ended with a backslash. This can occur when the application's development server is improperly exposed to the network. An attacker might craft requests that trigger this bug, thus successfully accessing files meant to be restricted like configuration files. This behavior is influenced by specific version configurations of Vite, necessitating careful version management to mitigate the issue.

Potential effects of this vulnerability include unauthorized access to sensitive application configuration files. Exploitation can lead to the disclosure of environment variables, internal data structures, or proprietary information. Attackers could utilize the accessed data for further attacks, such as privilege escalation or targeted exploitation of other vulnerabilities. This disclosure may also undermine trust in the application's data confidentiality. Preventive measures are crucial to avoid legal and reputational repercussions arising from data breaches.

REFERENCES

Solution Advice
  • Upgrade Vite to versions 5.4.21, 6.4.1, 7.0.8, or 7.1.11 or later to ensure server misconfiguration issues are fixed.
  • Ensure proper server settings, especially server.fs.deny, are applied to mitigate unauthorized file access.
  • Regularly audit and monitor server configurations to detect and prevent potential vulnerabilities quickly.
  • Utilize security tools to continuously scan for potential misconfigurations and information disclosure risks.
  • Implement access controls to restrict the exposure of development servers to trusted networks only.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.