Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
Vite's server.fs.deny bypassed with /. for files under project root
Vite's `server.fs.deny` did not deny requests for patterns with directories.
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
vite allows server.fs.deny bypass via backslash on Windows
Vite's `server.fs.deny` is bypassed when using `?import&raw`
Get SLA-backed support, security patches, and direct access to senior engineers for Vite — without relying on volunteer maintainers.
Talk to an Expert →