CVE-2025-31486 is an arbitrary file read vulnerability in Vite, a frontend tooling framework for JavaScript. In affected versions, the Vite development server's server.fs.deny restriction can be bypassed, allowing the contents of otherwise denied files to be returned to the browser. According to the provided content, the bypass can be triggered by appending ?.svg together with ?.wasm?init or by using a sec-fetch-dest: script header. The issue is only exploitable when the targeted file is smaller than build.assetsInlineLimit, which defaults to 4 kB, and affects Vite 6.0+ as described in the source material. The vulnerable condition is specifically tied to exposed Vite dev servers rather than production deployments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a hands-on, containerized lab environment to simulate and exploit the path traversal vulnerability in Vite's development server (CVE-2025-31486). The structure includes a Dockerfile to build and run a vulnerable Vite server, a full node_modules directory for dependencies, and static assets for the demo app. The README.md gives detailed instructions for launching the vulnerable server and performing the exploit, which involves sending a crafted HTTP request to the dev server (typically on port 5173) to read arbitrary files from the server's filesystem. The exploit leverages a flaw in Vite's asset plugin URL handling, bypassing security checks with suffixes like ?.svg. The repository is intended for educational and testing purposes, not for production use. No weaponized or automated exploit scripts are included; exploitation is performed manually via HTTP requests.
This repository contains a Python proof-of-concept (PoC) exploit for CVE-2025-31486, a vulnerability in Vite SSR (Server-Side Rendering) that allows arbitrary file read via crafted HTTP requests. The main file, 'CVE-2025-31486-PoC.py', takes a target URL as input and attempts to read sensitive files ('/etc/passwd' for Linux and 'C:\windows\win.ini' for Windows) by sending specially crafted GET requests to the server. If the server is vulnerable, it responds with base64-encoded file content, which the script decodes and validates. The exploit is network-based and does not require authentication. The repository also includes a README with basic usage instructions and a reference link for further details. The code is a standalone PoC and does not belong to any exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.