← Browse

CVE-2025-31125

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
58.5%
99.1th percentile
CISA KEV
Listed
Added 2026-01-22 · patch by 2026-02-12
Weakness / dates
Published — · modified —

Timeline

Description

Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.

Official: NVD · CVE.org