CVE-2025-57753

vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2.
CVSS

No CVSS.

Configurations

No configuration.

History

22 Aug 2025, 18:09

Type Values Removed Values Added
Summary
  • (es) vite-plugin-static-copy es rollup-plugin-copy para Vite compatible con el servidor de desarrollo. Se puede acceder a los archivos no incluidos en el archivo src mediante una solicitud específica. La vulnerabilidad se corrigió en las versiones 2.3.2 y 3.1.2.

21 Aug 2025, 18:15

Type Values Removed Values Added
References () https://github.com/sapphi-red/vite-plugin-static-copy/security/advisories/GHSA-pp7p-q8fx-2968 - () https://github.com/sapphi-red/vite-plugin-static-copy/security/advisories/GHSA-pp7p-q8fx-2968 -

21 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 16:15

Updated : 2025-08-22 18:09


NVD link : CVE-2025-57753

Mitre link : CVE-2025-57753

CVE.ORG link : CVE-2025-57753


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')