Package compatibility
Vite 2.5
What Node.js versions does this Vite version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >=12.2.0
- Tip version
- 2.9.18
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other Vite lines
Security
Advisories affecting Vite 2.5 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 14
- Known exploited
- 1
- Highest CVSS
- —
- CVE-2025-31125GHSA-4r4m-qw57-chr8Known exploited
Vite Vitejs Improper Access Control Vulnerability
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
- CISA KEV:
- listed · added 2026-01-22 · due 2026-02-12
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Affected:
- <4.5.11
- Fixed in:
- 4.5.11
- Source:
- OSV source · Advisory · CISA KEV
- CVE-2026-53632GHSA-v6wh-96g9-6wx3
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
- Affected:
- <6.4.3
- Fixed in:
- 6.4.3
- Source:
- OSV source
- CVE-2026-53571GHSA-fx2h-pf6j-xcff
vite: `server.fs.deny` bypass on Windows alternate paths
- Affected:
- <6.4.3
- Fixed in:
- 6.4.3
- Source:
- OSV source · Advisory
- CVE-2024-52011GHSA-c27g-q93r-2cwf
launch-editor vulnerable to command injection via the crafted request on Windows
- Affected:
- <5.4.9
- Fixed in:
- 5.4.9
- Source:
- OSV source · Advisory
- CVE-2026-39365GHSA-4w7w-66w2-5vf9
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
- Affected:
- <6.4.2
- Fixed in:
- 6.4.2
- Source:
- OSV source · Advisory
- CVE-2025-58751GHSA-g4jq-h2w9-997c
Vite middleware may serve files starting with the same name with the public directory
- Affected:
- <5.4.20
- Fixed in:
- 5.4.20
- Source:
- OSV source · Advisory
- CVE-2025-58752GHSA-jqfw-vq24-v9c3
Vite's `server.fs` settings were not applied to HTML files
- Affected:
- <5.4.20
- Fixed in:
- 5.4.20
- Source:
- OSV source · Advisory
- CVE-2025-46565GHSA-859w-5945-r5v3
Vite's server.fs.deny bypassed with /. for files under project root
- Affected:
- <4.5.14
- Fixed in:
- 4.5.14
- Source:
- OSV source · Advisory
- CVE-2025-32395GHSA-356w-63v5-8wf4
Vite has an `server.fs.deny` bypass with an invalid `request-target`
- Affected:
- <4.5.13
- Fixed in:
- 4.5.13
- Source:
- OSV source · Advisory
- CVE-2025-31486GHSA-xcj6-pq6g-qj4x
Vite allows server.fs.deny to be bypassed with .svg or relative paths
- Affected:
- <4.5.12
- Fixed in:
- 4.5.12
- Source:
- OSV source · Advisory
- CVE-2025-30208GHSA-x574-m823-4x7w
Vite bypasses server.fs.deny when using ?raw??
- Affected:
- <4.5.10
- Fixed in:
- 4.5.10
- Source:
- OSV source · Advisory
- CVE-2025-24010GHSA-vg6x-rcgg-rjx6
Websites were able to send any requests to the development server and read the response in vite
- Affected:
- <4.5.6
- Fixed in:
- 4.5.6
- Source:
- OSV source · Advisory
- CVE-2024-45812GHSA-64vr-g452-qvp3
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
- Affected:
- <3.2.11
- Fixed in:
- 3.2.11
- Source:
- OSV source · Advisory
- CVE-2024-45811GHSA-9cwx-2883-4wfx
Vite's `server.fs.deny` is bypassed when using `?import&raw`
- Affected:
- <3.2.11
- Fixed in:
- 3.2.11
- Source:
- OSV source · Advisory
