OSS Support Hub / Build Tool

Node.js Build Tool MIT Latest: v8.0.13

Vite

Next generation frontend tooling — fast dev server and optimized build

Project Health at a Glance

Live data from GitHub and npm, updated daily.

80.6K+13
GitHub Stars
📦
v8.0.13
Latest Release · Yesterday
🔄
3d
Avg. Release Cadence
🐛
720
Open Issues
📅
Today
Last Commit
⬇️
123.2M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)

Published: 2023-06-06 Fixed in: 2.9.16

Vite has an `server.fs.deny` bypass with an invalid `request-target`

Published: 2025-04-11 Fixed in: 6.2.6

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

Published: 2025-03-31 Fixed in: 6.2.4

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

Published: 2026-04-06 Fixed in: 8.0.5

Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS

Published: 2024-09-17 Fixed in: 5.4.6

Vite's server.fs.deny bypassed with /. for files under project root

Published: 2025-04-30 Fixed in: 6.3.4

Vite's `server.fs.deny` did not deny requests for patterns with directories.

Published: 2024-04-03 Fixed in: 2.9.18

Vite XSS vulnerability in `server.transformIndexHtml` via URL payload

Published: 2023-12-05 Fixed in: 4.4.12

vite allows server.fs.deny bypass via backslash on Windows

Published: 2025-10-20 Fixed in: 7.1.11

Vite's `server.fs.deny` is bypassed when using `?import&raw`

Published: 2024-09-17 Fixed in: 5.4.6

Alternatives to Vite

Other Build Tool projects in the Node.js ecosystem worth evaluating.

Support Options for Vite

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Vite — without relying on volunteer maintainers.

Talk to an Expert →