vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2. | |
| Title | vite-plugin-static-copy files not included in `src` are accessible with a crafted request | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-21T16:03:04.804Z
Updated: 2025-08-21T17:32:07.786Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57753
Updated: 2025-08-21T17:24:16.374Z
Status : Awaiting Analysis
Published: 2025-08-21T16:15:34.823
Modified: 2025-08-22T18:09:17.710
Link: CVE-2025-57753