Vendor
high
advisory
Vite Dev Server `server.fs.deny` Bypass on Windows (CVE-2026-53571)
2 rules 1 TTP 1 CVE 3 IOCsA high-severity vulnerability (CVE-2026-53571) in the Vite development server on Windows allows threat actors to bypass `server.fs.deny` restrictions, leading to information disclosure of sensitive files like `.env` or `tls.pem` via crafted HTTP requests utilizing NTFS Alternate Data Streams or 8.3 short names, impacting applications that expose the dev server to the network.
PoC
Vite +4
information-disclosure
bypass
web-vulnerability
windows
development-server
2r
1t
1c
3i
updated
high
advisory
Vite Arbitrary File Read Vulnerability via WebSocket
2 rules 1 TTPVite versions 6.0.0 to 8.0.4 are vulnerable to arbitrary file read, allowing attackers to bypass access controls and retrieve the contents of arbitrary files on the server via the WebSocket path when the dev server is exposed to the network.
Vite
file-read
vulnerability
websocket
2r
1t