Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
(opens in new tab)
(github.com)
2 points
lukax
2mo ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
lukax
OP
2mo ago
Combine that with CVE-2025-24010 and any website was able to read any file on developers' computers.
https://github.com/advisories/GHSA-vg6x-rcgg-rjx6
j
/
k
navigate · click thread line to collapse