An open index of dependabot pull requests across open source projects.

vite

Ecosystem:
npm
Package URL:
pkg:npm/vite
Total PRs:
123,102 Dependabot PRs
Latest PR:
about 3 hours ago
Unique Repositories:
49,782 repositories
Unique Repos (30 days):
272 repositories
Security Advisories
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
GHSA-4w7w-66w2-5vf9 CVE-2026-39365 MODERATE published 4 months ago • updated 4 days ago
### Summary Any files ending with `.map` even out side the project can be returned to the browser. ### Impact Only apps that match the following...
Vite middleware may serve files starting with the same name with the public directory
GHSA-g4jq-h2w9-997c CVE-2025-58751 LOW published 11 months ago • updated about 5 hours ago
### Summary Files starting with the same name with the public directory were served bypassing the `server.fs` settings. ### Impact Only apps that ...
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
GHSA-4r4m-qw57-chr8 CVE-2025-31125 MODERATE published over 1 year ago • updated 1 day ago
### Summary The contents of arbitrary files can be returned to the browser. ### Impact Only apps explicitly exposing the Vite dev server to the n...
Vite's `server.fs.deny` is bypassed when using `?import&raw`
GHSA-9cwx-2883-4wfx CVE-2024-45811 MODERATE published almost 2 years ago • updated 1 day ago
### Summary The contents of arbitrary files can be returned to the browser. ### Details `@fs` denies access to files outside of Vite serving allow...
Vite has an `server.fs.deny` bypass with an invalid `request-target`
GHSA-356w-63v5-8wf4 CVE-2025-32395 MODERATE published over 1 year ago • updated about 3 hours ago
### Summary The contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. ### Impact Only apps with ...
Recent PRs (filtered by: Patch PRs )
Bump vite from 7.3.5 to 7.3.6

getpostern/postern #10

7.3.5 → 7.3.6 Patch PR
Closed about 10 hours ago 2 comments
getpostern
Package Details
Name: vite
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/vite
JSON API: View JSON
Security Advisories

22

Active advisories
HIGH 7
MODERATE 13
LOW 2
View All npm Advisories
Package Information
Description:

Native-ESM powered web dev build tool

Repository: https://github.com/vitejs/vite
Homepage: https://vite.dev
Latest Release: 6.3.5
over 1 year ago
Dependent Repos: 363,358
Dependent Packages: 31,388
Downloads: 105,034,023
Ranking: Top 0.0591% by dependent repos Top 0.036% by downloads Top 0.0036% by dependent pkgs
PR Status
Open 59,149 (48.0%)
Merged 15,942 (13.0%)
Closed 43,581 (35.4%)
PR Types
Major 39,528 (32.1%)
Minor 23,794 (19.3%)
Patch 54,133 (44.0%)
Removal 1,056 (0.9%)