CVE-2025-30208 is an improper access-control vulnerability in Vite development servers prior to versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. The Vite @fs route is intended to deny access to files outside the configured serving allow list. Crafted query strings containing trailing separators, including ?raw?? or ?import&raw??, bypass this restriction because trailing question marks are removed during some processing stages but are not handled by the relevant query-string regular expressions. The bypass permits file contents to be returned to the requesting browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
--host or the server.host configuration option where untrusted users can reach the service until fixed Vite versions are deployed.Patch, then assume compromise.
15 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (16 hidden).
This 11-file repository is a deliberately vulnerable Dockerized Vite challenge demonstrating CVE-2025-30208, an unauthenticated arbitrary file-read flaw in Vite development servers. The application pins vite@5.4.14, runs its dev server on 0.0.0.0:5173, and maps host port 10015 to that service. At startup, entrypoint.sh takes GZCTF_FLAG or FLAG and writes it to /flag.txt, deliberately outside the /app project root. The main exploit is exploit/solve.py, a standard-library Python script. It accepts an optional host and port, requests /@fs/flag.txt?import&raw??, and parses the Vite raw-import JavaScript response for a WINS{...} value. The malformed query is the operative payload: it bypasses the strict server.fs allow-list check and turns an otherwise forbidden out-of-root file request into a successful disclosure. Although the implementation is tailored to flag retrieval, the vulnerability supplies a broader arbitrary readable-file primitive, as documented with /etc/passwd. Supporting files provide a minimal Vite page (src/index.html and src/src/main.js), an explicit strict filesystem configuration in src/vite.config.js, Docker build/run definitions, and Korean-language deployment/write-up documentation. No command execution, persistence, credential capture, or file modification is performed by the exploit itself; its capability is read-only disclosure. Updating Vite to a fixed version such as 5.4.15 or later and avoiding public exposure of development servers mitigates the demonstrated issue.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-30208 affecting exposed Vite development servers. The repo contains one executable script (CVE-2025-30208.py), a README describing the vulnerability and affected versions, and a minimal requirements.txt listing requests. The Python script is the main entry point and implements the full exploit workflow. It accepts a target base URL and a required remote file path to read, plus optional force mode, raw output mode, timeout, proxy, custom headers, and cookies. It first performs a vulnerability check unless --force is used: it requests the target's @vite/client endpoint to confirm the service looks like a Vite dev server, then fetches node_modules/vite/package.json to parse the Vite version and compare it against hardcoded vulnerable version ranges. If the target appears vulnerable, the exploit constructs crafted @fs URLs using the attacker-supplied file path and appends either ?import&raw?? or ?raw??. These malformed query strings are intended to bypass Vite's server.fs.deny protections and cause the dev server to return the contents of files that should normally be inaccessible. The script then prints the returned file contents. It can either display the raw HTTP response body or parse the common Vite response format of export default "..." into decoded text. Main exploit capability: arbitrary file read from the remote server hosting the exposed vulnerable Vite dev server. There is no code execution, persistence, or shell payload; the exploit is focused on information disclosure. Because it includes working exploitation logic and a usable payload path but no advanced framework integration or customizable post-exploitation, the maturity is best classified as OPERATIONAL.
Repository contains a single Python exploit tool (main.py, ~40KB) implementing an operational scanner/exploit for CVE-2025-30208 (Vite dev server arbitrary file read via @fs). The script provides a terminal UI (banner/spinner/sections), defines multiple bypass variants (query-string permutations like raw/import/url combinations and at least one header-based variant using sec-fetch-dest: script), and orchestrates a multi-phase workflow: Phase 1 Reconnaissance, Phase 2 Bypass Selection, Phase 3 Intelligence Gathering (stages named env/git/fs/topo), and an optional Phase 4 “Exploitation Chain” when --full-chain is enabled. It supports targeting a base URL (--target), optional stealth mode, proxying, timeouts, SSL verification toggle, reading a specific file path (--file), and saving results to JSON/Markdown reports (--output). Overall purpose: remotely retrieve arbitrary files from a vulnerable Vite dev server and automate collection/analysis of high-value artifacts (e.g., .env and git-related data) to support authorized security assessments.
This repository contains a Python proof-of-concept exploit for CVE-2025-30208, a local file inclusion (LFI) vulnerability in the Vite dev server. The exploit targets specific vulnerable versions of Vite (see README for affected versions) and leverages a crafted HTTP GET request to the @fs endpoint with a specially constructed query string (?import&raw??) to bypass file access restrictions. The main script, CVE-2025-30208.py, allows both command-line and interactive operation, enabling the user to specify a target URL and file path to read. The exploit is effective only if the Vite dev server is exposed to the network. The repository is well-structured, with a single code file, a README providing detailed usage and vulnerability information, and standard support files. No framework is used; the exploit is standalone. The main fingerprintable endpoint is the crafted @fs path on the Vite dev server, and the default demonstration targets /etc/passwd. The exploit's primary capability is to exfiltrate arbitrary file contents from the server's filesystem.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-30208, a Local File Inclusion (LFI) vulnerability in the Vite development server. The exploit is implemented in a single Python script (CVE-2025-30208.py) and is accompanied by a detailed README.md explaining the vulnerability, affected versions, mitigation steps, and usage instructions. The Python script allows an attacker to target either a single Vite dev server or a batch of targets, attempting to read arbitrary files from the server's filesystem by exploiting a flaw in the @fs endpoint's path filtering. The script supports custom file paths, bypass query strings, proxying, and multi-threaded batch exploitation. It verifies exploitation by checking for known file contents (e.g., 'root:/bin/bash' in /etc/passwd) and saves successful results to disk. The exploit targets Vite dev servers running vulnerable versions (prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, or 4.5.10) that are exposed to the network. The main attack vector is network-based, leveraging crafted HTTP requests to the /@fs/<file_path>?<bypass_query> endpoint. The script is a functional PoC and does not include weaponized or post-exploitation payloads. No hardcoded IPs or domains are present; the script is designed for user-supplied targets. The repository is well-structured, with clear documentation and usage examples, and is intended for research and educational purposes only.
This repository contains a Bash script exploit for CVE-2025-30208, a Local File Inclusion (LFI) vulnerability in the Vite development server. The exploit script (CVE-2025-30208.sh) automates the process of testing a target web server for LFI by sending HTTP requests to a variety of crafted endpoints (such as /@fs/{path}?raw?? and /app/{path}?raw??), substituting {path} with a comprehensive list of sensitive file paths (e.g., /etc/passwd, .env, root/.ssh/authorized_keys, etc.). The script supports a 'bypass' mode, which iterates through multiple payload variations to evade potential filters, and allows specifying a custom file to target. The README provides usage instructions and a Google dork for identifying potentially vulnerable targets. The exploit is operational and can retrieve sensitive files from vulnerable Vite servers accessible over the network. No payload for code execution is included; the exploit is focused on file read via LFI. The repository structure is simple, containing only the exploit script and a README.
This repository provides an advanced Python-based exploit and scanner for CVE-2025-30208, a critical arbitrary file read vulnerability in the Vite development server. The main exploit logic resides in 'CVE-2025-30208.py', which implements a modular, interactive command-line tool. The tool allows users to configure targets (host, port), set custom HTTP headers, use proxies, and perform both single and batch scans. It leverages a large set of payload variations (defined in 'payloads.py') to target Vite's file system endpoints (such as /@fs/{file_path}?raw?? and /app/{file_path}?raw??), attempting to read a comprehensive list of sensitive files (from 'sensitive_files.py'). The tool supports session management, error handling, rate limiting, and generates detailed reports in HTML and JSON formats (using 'html_template.py'). It is designed for professional penetration testing and security research, with features for session saving, web-based report viewing, and multi-threaded scanning. The exploit is operational and can be used to confirm and demonstrate the impact of the vulnerability on affected Vite servers.
This repository is a professional-grade exploit and scanner for CVE-2025-30208, a critical arbitrary file read vulnerability in the Vite development server. The main exploit logic resides in 'CVE-2025-30208.py', which provides an interactive command-line interface for configuring targets, running scans, and generating reports. The tool is modular, with 'payloads.py' containing over 60 payload variations for exploiting the vulnerable endpoints (primarily /@fs/{file_path}?raw?? and variants), and 'sensitive_files.py' listing over 200 sensitive files to target for information disclosure. The tool supports batch scanning, proxy configuration, custom headers, rate limiting, session management, and generates both HTML and JSON reports. It is designed for authorized penetration testing and security research, with strong input validation and error handling. The exploit targets Vite servers running vulnerable versions (<=6.2.2 and several earlier versions) on any platform (Linux, Windows, macOS). The attack vector is network-based, requiring HTTP access to the Vite server. The tool is operational and suitable for real-world exploitation and vulnerability assessment.
This repository contains three POC exploit scripts for pre-auth arbitrary file read vulnerabilities in the Vite development server, targeting CVE-2025-30208, CVE-2025-31125, and CVE-2025-31486. The main exploit files are Python scripts using the pocsuite3 framework, each implementing a _verify method that attempts to read sensitive files (such as /etc/passwd or C:/Windows/win.ini) from a vulnerable Vite server by sending crafted HTTP requests to specific endpoints. The exploits leverage different URL query parameter tricks and, in some cases, specific HTTP headers to bypass access controls and trigger the vulnerability. The repository also includes a 'vuln-env' directory, which provides a ready-to-use vulnerable Vite environment for local testing, complete with configuration files and a sample Vue project. The README.md provides detailed background, affected versions, POC usage instructions, and an in-depth analysis of the vulnerabilities and their fixes. The exploits are proof-of-concept in nature, demonstrating the ability to read arbitrary files from the server without authentication, and are suitable for security testing and research.
This repository, 'ViteVulScan', is a Go-based operational exploit tool targeting three Vite development server vulnerabilities: CVE-2025-30208, CVE-2025-31125, and CVE-2025-31486. The tool enables detection and exploitation of arbitrary file read vulnerabilities on both Linux and Windows platforms. It supports single-target and batch exploitation, including integration with the Fofa asset search platform for mass scanning. The main logic is implemented in the 'cmd' directory, with separate modules for each CVE, command-line parsing, Fofa integration, and exploitation routines. Sensitive file paths for exploitation are provided in the 'dict' directory for both Linux and Windows. The tool can perform deep exploitation, reading and saving a wide range of sensitive files from vulnerable servers. Results are saved in a structured format under the 'result' directory. The repository is mature, operational, and suitable for both targeted and mass exploitation scenarios.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-30208, a path traversal vulnerability in Vite's /@fs/ route that allows arbitrary file read on the server. The exploit is implemented in Python (cve-2025-30208.py) and is accompanied by a detailed README.md explaining the vulnerability, affected versions, and usage instructions. The script can target a single Vite server or multiple servers in batch mode, supports custom file paths and bypass queries, and can use a proxy for requests. It verifies vulnerability by attempting to read known files (e.g., /etc/passwd, C:/windows/win.ini) and, if successful, reads and saves the contents of arbitrary files specified by the user. The main attack vector is network-based, exploiting HTTP requests to the /@fs/ endpoint with crafted query strings to bypass Vite's path validation. The exploit is a functional PoC and does not include weaponized or post-exploitation features.
This repository contains a Python exploit tool for CVE-2025-30208, an arbitrary file read vulnerability in the Vite development server. The main file, CVE-2025-30208.py, is a command-line utility that allows the user to test a target Vite server for the vulnerability by attempting to read sensitive files using the /@fs/<filepath>?import&raw?& endpoint. The tool supports reading arbitrary files, performing basic and deep system fingerprinting (including OS detection, privilege configuration, web server and cloud environment analysis), and generates a risk report based on the files it can access. It supports both Linux and Windows targets, and can use an HTTP/HTTPS proxy. The README.md provides detailed usage instructions, parameter descriptions, and legal disclaimers. The exploit is operational and provides real file read capability, not just detection. The main attack vector is network-based, targeting accessible Vite dev servers. Numerous fingerprintable file paths are used for system and environment analysis.
This repository contains a Python proof-of-concept exploit for CVE-2025-30208, an arbitrary file read vulnerability in the Vite development server (versions <= 6.2.2, <= 6.1.1, <= 6.0.11, <= 5.4.14, <= 4.5.9). The exploit leverages a flaw in the handling of query parameters, allowing attackers to bypass file access restrictions by appending '?raw' to file read requests. The main script, 'CVE-2025-30208.py', allows users to test single or multiple targets for vulnerability, specify the file to read (defaulting to '/etc/passwd'), and optionally output results to a file. The script uses HTTP requests to interact with the Vite dev server and checks for successful file reads. The repository also includes a README with detailed usage instructions and a requirements.txt listing necessary Python dependencies. The exploit is a POC and does not include weaponized or post-exploitation features.
This repository contains a Python-based scanner and exploit tool for CVE-2025-30208, a vulnerability in the Vite Dev Server. The main file, 'exploit.py', provides both detection and exploitation capabilities. It can scan a single URL or multiple URLs (from a file) for the vulnerability by sending crafted HTTP GET requests with specific payloads (e.g., '?raw??', '?import&raw??'). If a target is found vulnerable, the tool attempts to exploit it by reading the '/etc/passwd' file, demonstrating arbitrary file read. Results are saved to 'vulnerable.txt' (for detected vulnerabilities) and 'exploited.txt' (for successful file reads). The code uses multi-threading for mass scanning and is intended for use by security researchers. The repository structure is simple, consisting of a README.md with usage instructions and the main exploit script 'exploit.py'.
This repository provides an operational Python exploit for CVE-2025-30208, a critical arbitrary file read vulnerability in the Vite development server. The main script, 'Vite-CVE-2025-30208-EXP.py', allows users to test single URLs or batches of targets (from a file), optionally using a proxy. It supports custom payloads (file paths) and dictionary-based fuzzing (using 'dict.txt') to attempt reading a wide range of sensitive files on the target server. The exploit works by sending crafted HTTP GET requests to the Vite dev server, appending various query parameters to the file path in order to bypass potential filters and trigger the vulnerability. Successful exploitation is detected by searching for known markers (e.g., 'root:' in /etc/passwd) in the response, and results are saved to 'output.txt'. The repository includes a README with usage instructions, a requirements.txt for dependencies, and a large dictionary of file paths for fuzzing. The exploit is not a simple PoC; it is operational and automates detection and exploitation across multiple targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Vite vulnerability leveraged as part of the reported scanning and credential-theft campaign; no technical details are provided.
A vulnerability involving file-access bypass techniques that generated signatures in traffic associated with the Vite scanning campaign.
A vulnerability involving file-access bypass techniques that was detected in the Vite-focused scanning traffic.
An arbitrary file-disclosure vulnerability in Vite, mentioned only as an associated GreyNoise scanner tag amid credential-file probing activity.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.