fix: update vite to >=6.4.2 to patch arbitrary file read vulnerability (#37)
Vite versions >=6.0.0 <=6.4.1 are vulnerable to arbitrary file read via the Vite Dev Server WebSocket (server.fs.deny bypass with queries). CVE: GHSA-p9ff-h696-f583 Co-authored-by: Gandalf the Greybeard <gandalf@privilegedescalation.dev> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
This commit was merged in pull request #37.
This commit is contained in:
committed by
GitHub
parent
39ed3ea90a
commit
d44ae043c3
+2
-1
@@ -45,6 +45,7 @@
|
||||
},
|
||||
"overrides": {
|
||||
"tar": "^7.5.11",
|
||||
"undici": "^7.24.3"
|
||||
"undici": "^7.24.3",
|
||||
"vite": ">=6.4.2"
|
||||
}
|
||||
}
|
||||
|
||||
Generated
+1057
-643
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user