Vulnerability threat dossier

CVE-2024-45811

vitejsvite

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue has been patched in versions 5.4.6, 5.3.6, 5.2.14, 4.5.5, and 3.2.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

VTP deterministic threat16.7of 100 · CVSS excluded

VTP analyst assessment

Vite development-server file disclosure

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence78%
Public exploitation · VTP factREPORTED

Assessment

BleepingComputer reports mass scanning of internet-exposed Vite development servers to steal cloud credentials and configuration. CVE-2024-45811 lets a requester bypass Vite's @fs serving restriction with ?import&raw and return existing file contents.

Why it matters

  • An exposed development server can disclose files outside its intended serving allow list.
  • Disclosed cloud credentials or configuration can enable access beyond the development server.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

BleepingComputer reports the campaign; the available record does not independently confirm its scale or specific victim impact.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Vite development servers, remove them from internet exposure and upgrade to 5.4.6, 5.3.6, 5.2.14, 4.5.5, or 3.2.11 or later.

AI baseline history (2)
  1. BASELINE ASSESSED
    Vite development-server file disclosuregpt-5.6-terra · low
  2. BASELINE ASSESSED
    Reported exploitation associated with exposed Vite development serversgpt-5.6-terra · low
Technical severityMEDIUMCVSS 4.8 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0163th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:9171ef56ec47decf3ccc695ba03325407e7c4af191ebcdb3972100d92c2a0978ACTIVE
Evidence
04

Event history

Threat timeline

  1. 16:1514 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]

CVE-2024-45811CVE-2025-30208CVE-2025-31125CVE-2026-39364
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score16.7vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.21 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
4.8 · MEDIUM
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE
CWE-200, CWE-284
CPE records
0
Deterministic history records
9
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.