CVE 2.9 LOW

Cloudflare vite plugin exposes secrets over the built-in dev server_CVE-2025-59427

2.9 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Description

The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars. This vulnerability is fixed in 1.6.0.

Basic Information

ID CVE-2025-59427
Source GitHub_M
Published Sep 19, 2025 at 15:30

Affected Product

Vendor cloudflare
Product workers-sdk
Version < 1.6.0
Affected Versions cloudflare workers-sdk < 1.6.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.