Sploitus

CVE-2025-59427

No indexed exploits for CVE-2025-59427 yet

The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars. This vulnerability is fixed in 1.6.0.

Fix
Available
CVSS 4.0
6.3 MEDIUM
EPSS
0.4% (28th percentile)
Weakness
CWE-200
NVD status
Deferred
Published
2025-09-19
CVE-2025-59427 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-59427 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-59427 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.