The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars. This vulnerability is fixed in 1.6.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
19 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-19 16:15
Updated : 2025-09-22 21:23
NVD link : CVE-2025-59427
Mitre link : CVE-2025-59427
CVE.ORG link : CVE-2025-59427
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor