Miggo Logo

CVE-2025-32395:
Vite has an `server.fs.deny` bypass with an invalid `request-target`

6

CVSS Score
4.0

Basic Information

EPSS Score
0.03715%
Published
4/11/2025
Updated
4/11/2025
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Package NameEcosystemVulnerable VersionsFirst Patched Version
vitenpm>= 6.2.0, < 6.2.66.2.6
vitenpm>= 6.1.0, < 6.1.56.1.5
vitenpm>= 6.0.0, < 6.0.156.0.15
vitenpm>= 5.0.0, < 5.4.185.4.18
vitenpm< 4.5.134.5.13

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Summ*ry T** *ont*nts o* *r*itr*ry *il*s **n ** r*turn** to t** *rows*r i* t** **v s*rv*r is runnin* on No** or *un. ### Imp**t Only *pps wit* t** *ollowin* *on*itions *r* *****t**. - *xpli*itly *xposin* t** Vit* **v s*rv*r to t** n*twork (usin*

Reasoning

No *n*lysis *v*il**l*