An open index of dependabot pull requests across open source projects.

vite

Ecosystem:
npm
Package URL:
pkg:npm/vite
Total PRs:
122,995 Dependabot PRs
Latest PR:
about 4 hours ago
Unique Repositories:
49,706 repositories
Unique Repos (30 days):
181 repositories
Security Advisories
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
GHSA-4w7w-66w2-5vf9 CVE-2026-39365 MODERATE published 4 months ago • updated 4 days ago
### Summary Any files ending with `.map` even out side the project can be returned to the browser. ### Impact Only apps that match the following...
Vite has an `server.fs.deny` bypass with an invalid `request-target`
GHSA-356w-63v5-8wf4 CVE-2025-32395 MODERATE published over 1 year ago • updated about 12 hours ago
### Summary The contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. ### Impact Only apps with ...
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
GHSA-4r4m-qw57-chr8 CVE-2025-31125 MODERATE published over 1 year ago • updated about 12 hours ago
### Summary The contents of arbitrary files can be returned to the browser. ### Impact Only apps explicitly exposing the Vite dev server to the n...
Vite's `server.fs.deny` is bypassed when using `?import&raw`
GHSA-9cwx-2883-4wfx CVE-2024-45811 MODERATE published almost 2 years ago • updated about 21 hours ago
### Summary The contents of arbitrary files can be returned to the browser. ### Details `@fs` denies access to files outside of Vite serving allow...
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
GHSA-353f-5xf4-qw67 CVE-2023-34092 HIGH published about 3 years ago • updated about 21 hours ago
The issue involves a security vulnerability in Vite where the server options can be bypassed using a double forward slash (`//`). This vulnerabilit...
Recent PRs
Bump esbuild and vite

jorzism-dotcom/SBM #11

5.4.21 → 8.1.5 Major PR
Open 12 days ago 3 comments
jorzism-dotcom
Package Details
Name: vite
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/vite
JSON API: View JSON
Security Advisories

22

Active advisories
HIGH 7
MODERATE 13
LOW 2
View All npm Advisories
Package Information
Description:

Native-ESM powered web dev build tool

Repository: https://github.com/vitejs/vite
Homepage: https://vite.dev
Latest Release: 6.3.5
over 1 year ago
Dependent Repos: 363,358
Dependent Packages: 31,388
Downloads: 105,034,023
Ranking: Top 0.0591% by dependent repos Top 0.036% by downloads Top 0.0036% by dependent pkgs
PR Status
Open 59,119 (48.1%)
Merged 15,942 (13.0%)
Closed 43,502 (35.4%)
PR Types
Major 39,494 (32.1%)
Minor 23,729 (19.3%)
Patch 54,123 (44.0%)
Removal 1,056 (0.9%)