Sploitus

CVE-2025-30208

50 known exploits for CVE-2025-30208

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

Affected products
Vite
Vitejs Vite
< 4.5.10, 5.4.15, 6.0.12, 6.1.2, 6.2.3
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
75.0% (99th percentile)
Weakness
CWE-200, CWE-284
NVD status
Analyzed
Published
2025-03-24
CVE-2025-30208 at NVD
Authoritative description, scoring and affected products

50 known exploits for CVE-2025-30208

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2025-30208
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208-31125-31486-32395
2026-09-10 KitPloitKITPLOIT
Vite-CVE-2025-30208-EXP
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208-ViteVulnScanner
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208-template
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208-EXP
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208
2026-09-10 KitPloitKITPLOIT
ViteVulScan
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208-Series
2026-09-10 KitPloitKITPLOIT
CVE-2025-30208-PoC
2026-09-09 KitPloitKITPLOIT
CVE-2025-30208_POC
2026-09-09 KitPloitKITPLOIT
CVE-2025-30208-Vite
2026-09-08 KitPloitKITPLOIT
CVE-2025-30208
2026-09-08 KitPloitKITPLOIT
Vite-CVE-2025-30208-Scanner
2026-09-07 KitPloitKITPLOIT
CVE-2025-30208-PoC
2026-09-07 KitPloitKITPLOIT
CVE-2025-30208
2026-09-07 KitPloitKITPLOIT
CVE-2025-30208
2026-09-06 KitPloitKITPLOIT
CVE-2025-30208
2026-09-06 KitPloitKITPLOIT
CVE-2025-30208
2026-09-05 KitPloitKITPLOIT
Exploit for Improper Access Control in Vitejs Vite
2026-06-16 cc3305GITHUB
πŸ“„ Vite 6.2.2 Arbitrary File Read
2026-03-10 indoushkaPACKETSTORMPHP
Exploit for Improper Access Control in Vitejs Vite
2026-03-04 HazaVVIPGITHUB
πŸ“„ Kubio AI Page Builder 2.5.1 PHP LFI Extractor Scanner
2025-12-18 indoushkaPACKETSTORMPHP
Exploit for CVE-2025-30208
2025-07-10 gonn4cryGITHUB
πŸ“„ Vite Local File Inclusion
2025-06-30 nu11secur1tyPACKETSTORMPython
Exploit for CVE-2025-30208
2025-06-29 TH-SecForgeGITHUB
Exploit for CVE-2025-30208
2025-06-27 ThemeHackersGITHUB
Exploit for CVE-2025-30208
2025-06-25 B1ack4shGITHUB
Exploit for CVE-2025-30208
2025-06-06 HaGsecGITHUB
Exploit for CVE-2025-30208
2025-04-24 r0ngy40GITHUB
Exploit for CVE-2025-30208
2025-04-21 imbas007GITHUB
πŸ“„ Vite 6.2.2 Arbitrary File Read
2025-04-03 Sheikh Mohammad HasanPACKETSTORM
Vite 6.2.2 - Arbitrary File Read
2025-04-03 4m3rr0rEXPLOITDB
Exploit for CVE-2025-30208
2025-04-03 4m3rr0rGITHUB
Exploit for CVE-2025-30208
2025-03-31 jackieyaGITHUB
Exploit for CVE-2025-30208
2025-03-31 jackieyaGITHUB
Exploit for CVE-2025-30208
2025-03-31 jackieyaGITHUB
Exploit for CVE-2025-30108
2025-03-27 4xuraGITHUB
Exploit for CVE-2025-30208
2025-03-27 4xuraGITHUB
Exploit for CVE-2025-30208
2025-03-27 On1onssGITHUB
Exploit for CVE-2025-30208
2025-03-27 iSee857GITHUB
Exploit for CVE-2025-30208
2025-03-26 ThumpBoGITHUB
Exploit for CVE-2025-30208
2025-03-26 xuemian168GITHUB
Exploit for CVE-2025-30208
2025-03-26 xaitxGITHUB
Exploit for CVE-2025-30208
2025-03-26 YuanBenSirGITHUB
Exploit for CVE-2025-30208
2025-03-21 LiChaserGITHUB