Package compatibility

Vite 2.5

What Node.js versions does this Vite version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>=12.2.0
Tip version
2.9.18
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Vite lines

Security

Advisories affecting Vite 2.5 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
14
Known exploited
1
Highest CVSS
  • CVE-2025-31125GHSA-4r4m-qw57-chr8Known exploited

    Vite Vitejs Improper Access Control Vulnerability

    Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

    CISA KEV:
    listed · added 2026-01-22 · due 2026-02-12
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    <4.5.11
    Fixed in:
    4.5.11
  • CVE-2026-53632GHSA-v6wh-96g9-6wx3

    launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

    Affected:
    <6.4.3
    Fixed in:
    6.4.3
    Source:
    OSV source
  • CVE-2026-53571GHSA-fx2h-pf6j-xcff

    vite: `server.fs.deny` bypass on Windows alternate paths

    Affected:
    <6.4.3
    Fixed in:
    6.4.3
    Source:
    OSV source · Advisory
  • CVE-2024-52011GHSA-c27g-q93r-2cwf

    launch-editor vulnerable to command injection via the crafted request on Windows

    Affected:
    <5.4.9
    Fixed in:
    5.4.9
    Source:
    OSV source · Advisory
  • CVE-2026-39365GHSA-4w7w-66w2-5vf9

    Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

    Affected:
    <6.4.2
    Fixed in:
    6.4.2
    Source:
    OSV source · Advisory
  • CVE-2025-58751GHSA-g4jq-h2w9-997c

    Vite middleware may serve files starting with the same name with the public directory

    Affected:
    <5.4.20
    Fixed in:
    5.4.20
    Source:
    OSV source · Advisory
  • CVE-2025-58752GHSA-jqfw-vq24-v9c3

    Vite's `server.fs` settings were not applied to HTML files

    Affected:
    <5.4.20
    Fixed in:
    5.4.20
    Source:
    OSV source · Advisory
  • CVE-2025-46565GHSA-859w-5945-r5v3

    Vite's server.fs.deny bypassed with /. for files under project root

    Affected:
    <4.5.14
    Fixed in:
    4.5.14
    Source:
    OSV source · Advisory
  • CVE-2025-32395GHSA-356w-63v5-8wf4

    Vite has an `server.fs.deny` bypass with an invalid `request-target`

    Affected:
    <4.5.13
    Fixed in:
    4.5.13
    Source:
    OSV source · Advisory
  • CVE-2025-31486GHSA-xcj6-pq6g-qj4x

    Vite allows server.fs.deny to be bypassed with .svg or relative paths

    Affected:
    <4.5.12
    Fixed in:
    4.5.12
    Source:
    OSV source · Advisory
  • CVE-2025-30208GHSA-x574-m823-4x7w

    Vite bypasses server.fs.deny when using ?raw??

    Affected:
    <4.5.10
    Fixed in:
    4.5.10
    Source:
    OSV source · Advisory
  • CVE-2025-24010GHSA-vg6x-rcgg-rjx6

    Websites were able to send any requests to the development server and read the response in vite

    Affected:
    <4.5.6
    Fixed in:
    4.5.6
    Source:
    OSV source · Advisory
  • CVE-2024-45812GHSA-64vr-g452-qvp3

    Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS

    Affected:
    <3.2.11
    Fixed in:
    3.2.11
    Source:
    OSV source · Advisory
  • CVE-2024-45811GHSA-9cwx-2883-4wfx

    Vite's `server.fs.deny` is bypassed when using `?import&raw`

    Affected:
    <3.2.11
    Fixed in:
    3.2.11
    Source:
    OSV source · Advisory