CVE-2025-31125
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
58.5%
99.1th percentile
CISA KEV
Listed
Added 2026-01-22 · patch by 2026-02-12
Weakness / dates
—
Published — · modified —
Description
Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.