8.0.8
5 years ago
2 days ago
Known vulnerabilities in the vite package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
vite is a Native-ESM powered web dev build tool Affected versions of this package are vulnerable to Incorrect Behavior Order: Validate Before Canonicalize through the Note: This is only exploitable if the development server is explicitly exposed to the network, the sensitive file exists within directories allowed by How to fix Incorrect Behavior Order: Validate Before Canonicalize? Upgrade | >=7.1.0 <7.3.2>=8.0.0 <8.0.5 |
vite is a Native-ESM powered web dev build tool Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the Note: This is only exploitable if the development server is started with network exposure (such as using How to fix Missing Authentication for Critical Function? Upgrade | >=6.0.0 <6.4.2>=7.0.0 <7.3.2>=8.0.0 <8.0.5 |
vite is a Native-ESM powered web dev build tool Affected versions of this package are vulnerable to Directory Traversal via the handling of Note: This is only exploitable if the dev server is started with the How to fix Directory Traversal? Upgrade | <6.4.2>7.0.0 <7.3.2>8.0.0 <8.0.5 |