MIRAGE
Threat IntelligenceCVEs › CVE-2025-30208

CVE-2025-30208 — exposed on the internet

Internet exposure observed by OffSeq scans · last 30 days

7
Exposed hosts
5.3
CVSS
75.0%
EPSS

Found on 7 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2025-30208

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

CWE-200CWE-284

OffSeq internet scanning found CVE-2025-30208 on 7 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

http grafana

Open the live CVE-2025-30208 view →

References