High SEVERITY — Vulnerability

CVE-2026-53571 — Vite is a frontend tooling framework for JavaScript.

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such a

Platform
Windows Server
CVE Record
CVE-2026-53571
CVSS Score
8.2/10
Published
22 June 2026
Views
3
Primary source: Review the official advisory at nvd.nist.gov Kaynağa Git

Summary

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw are treated as allowed paths, while Windows resolves them to the original file's default data stream. Similarly, Windows allows accessing a file using a different name with the 8.3 short name compatibility feature. Vite did not reject access via these alternate names. This vulnerability is fixed in 8.0.16, 7.3.5, and 6.4.3.

Assessment

  • CVE: CVE-2026-53571
  • Base CVSS score: 8.2
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Source: NVD entry

References

Actions

  • Verify affected systems in inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until the patch is applied
vite * vite\+ * windows -

Windows Server — Related Advisories

VIEW ALL →