{"id":"CVE-2023-34092","summary":"Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)","details":"Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings (`['.env', '.env.*', '*.{crt,pem}']`). Only users explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in vite@4.3.9, vite@4.2.3, vite@4.1.5, vite@4.0.5, vite@3.2.7, and vite@2.9.16.","aliases":["GHSA-353f-5xf4-qw67"],"modified":"2026-08-12T03:51:34.678374898Z","published":"2023-06-01T16:29:51.428Z","database_specific":{"cwe_ids":["CWE-200","CWE-50"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34092.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34092.json"},{"type":"ADVISORY","url":"https://github.com/vitejs/vite/security/advisories/GHSA-353f-5xf4-qw67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34092"},{"type":"FIX","url":"https://github.com/vitejs/vite/commit/813ddd6155c3d54801e264ba832d8347f6f66b32"},{"type":"FIX","url":"https://github.com/vitejs/vite/pull/13348"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vitejs/vite","events":[{"introduced":"af6088f40ad89579f39f8d2d93ae2d11168847c1"},{"fixed":"494f36b6678d135b376a104ca0309dc75af4e2f2"},{"introduced":"566d4c7bb51cf56550a5374ee46e1e1cbea1cf1f"},{"fixed":"2f5827c84884edd4ca2256b7c1f7959edf05a1f7"},{"introduced":"c57c21cc36d953d36a518226cbc06fb92b48a784"},{"fixed":"b1b3beb9f4f65f2b6042316a0c01005ad82f7884"},{"introduced":"9dbb7f7765fd7d255daf82ad44fe867d49f0befd"},{"fixed":"3ac6e91b1d626ee9e794b790f66c5e1750e465eb"},{"introduced":"d6468a3b1fa11f066a0f38515874f71da7b9640e"},{"fixed":"a460a2b3ef428986ed1e04a63f558331a7fdc94f"},{"introduced":"3a5543db215cedbcadcfa2e14a1c48b14acdd3c5"},{"fixed":"813ddd6155c3d54801e264ba832d8347f6f66b32"}],"database_specific":{"cpe":["cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*","cpe:2.3:a:vitejs:vite:2.9.15:*:*:*:*:node.js:*:*"],"extracted_events":[{"introduced":"3.0.2"},{"fixed":"3.2.7"},{"introduced":"4.0.0"},{"fixed":"4.0.5"},{"introduced":"4.1.0"},{"fixed":"4.1.5"},{"introduced":"4.2.0"},{"fixed":"4.2.3"},{"introduced":"4.3.0"},{"fixed":"4.3.9"},{"introduced":"2.9.15"},{"last_affected":"2.9.15"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.9.15","v3.2.6","v4.0.4","v4.1.4","v4.2.2","plugin-legacy@4.0.4","v4.3.8","v4.3.7","v4.3.6","v4.3.5","v4.3.4","v4.3.3","create-vite@4.3.1","plugin-legacy@4.0.3","v4.3.2","v4.3.1","create-vite@4.3.0","v4.3.0","v3.2.5","v4.2.1","create-vite@4.2.0","plugin-legacy@4.0.2","v4.2.0","v4.1.3","v4.1.2","v4.1.1","plugin-legacy@4.0.1","create-vite@4.1.0","plugin-legacy@4.0.0","v4.1.0","v4.0.3","v4.0.2","v4.0.1","create-vite@4.0.0","plugin-legacy@3.0.1","plugin-legacy@3.0.0","v4.0.0","v3.2.4","create-vite@3.2.1","plugin-legacy@2.3.1","plugin-vue-jsx@2.1.1","v3.2.3","v3.2.2","v3.2.1","create-vite@3.2.0","plugin-legacy@2.3.0","plugin-react@2.2.0","plugin-vue-jsx@2.1.0","plugin-vue@3.2.0","v3.2.0","v3.2.0-beta.4","v3.2.0-beta.3","v3.2.0-beta.2","v3.2.0-beta.1","plugin-legacy@2.3.0-beta.0","plugin-react@2.2.0-beta.0","plugin-vue-jsx@2.1.0-beta.0","plugin-vue@3.2.0-beta.0","v3.2.0-beta.0","v3.1.3","plugin-legacy@2.2.0","v3.1.2","v3.1.1","create-vite@3.1.0","plugin-legacy@2.1.0","plugin-react@2.1.0","plugin-vue@3.1.0","v3.1.0","v3.1.0-beta.2","plugin-vue-jsx@2.0.1","plugin-legacy@2.1.0-beta.0","plugin-vue@3.1.0-beta.0","plugin-react@2.1.0-beta.0","v3.1.0-beta.1","v3.1.0-beta.0","v3.0.9","v3.0.8","create-vite@3.0.2","plugin-vue@3.0.3","v3.0.7","create-vite@3.0.1","plugin-legacy@2.0.1","plugin-react@2.0.1","plugin-vue@3.0.2","v3.0.6","v3.0.5","v3.0.4","v3.0.3","v3.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34092.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}