CVE-2025-24010 – Vite WebSocket CORS Bypass

The following table lists the changes that have been made to the
CVE-2025-24010 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 20, 2025

    Action Type Old Value New Value
    Added Description Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
    Added CWE CWE-346
    Added CWE CWE-350
    Added CWE CWE-1385
    Added Reference https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6
Share the Post:

Related Posts