Back to Database
Status published
Medium
CVE-2022-35204
Vitejs Vite before v2.9.13 was discovered to allow attackers to...
Vulnerability Description
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-35204
Credits & Attribution
No credits recorded in the NVD database.
References
More from vitejs
View All →CVE-2025-68155
@vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Development
High
7.5
CVE-2025-67489
@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
Critical
9.8
CVE-2025-62522
vite allows server.fs.deny bypass via backslash on Windows
Medium
6
CVE-2025-58752
Vite's `server.fs` settings were not applied to HTML files
Low
2.3
CVE-2025-58751
Vite middleware may serve files starting with the same name with the public directory
Low
2.3
Affected Vendor
vitejs
View all reports →Affected Software
vite
Vulnerable Versions:
0
Timeline
Official Publish:
August 18th, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.