DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CVE-2025-24010

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-24010

Severity

6.5

Medium

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

Summary

Vite allows any websites to send any requests to the development server and read the response

Description

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-24010

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing