CVE-2025-59427 affects the Cloudflare Vite plugin, which provides integration between Vite and the Workers runtime. In the plugin's default configuration, the local development server exposes all files, including files in the project root that may contain sensitive information such as .env and .dev.vars. As a result, secrets intended only for local development can be retrieved through the dev server. The issue is fixed in version 1.6.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit for CVE-2025-59427, targeting web applications protected by Cloudflare or similar WAFs that return HTTP 403 Forbidden responses. The main file, main.py, is a comprehensive script that automates attempts to bypass 403 restrictions by generating a wide variety of HTTP request payloads. These include path manipulations (such as traversal, encoding, and appending special characters) and a large set of HTTP header manipulations (spoofing internal IPs, various X-Forwarded-* headers, Authorization, etc.). The script can take a single URL or a file containing multiple targets, detects if the target is behind Cloudflare (via headers and DNS), and, if so, attempts to access sensitive files like /etc/passwd. The script is interactive, color-coded, and limits the number of requests per target to avoid excessive traffic. No weaponized payload is included; the script is a POC for bypassing access controls, not for post-exploitation. The only code file is main.py, and the README provides a reference to the CVE. The exploit is network-based and does not require local access.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.