Skip to content

Vite security vulnerability #32945

@manojsridharsrinivasan

Description

@manojsridharsrinivasan

Command

other

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

There is a reported security vulnerability in Vite 7.3.1 (GHSA-p9ff-h696-f583). The latest @angular/build version 21.2.6 still depends on Vite 7.3.1, which introduces a transitive dependency vulnerability in Angular CLI projects.

Related issue - GHSA-v2wj-q39q-566r

Minimal Reproduction

N/A

Exception or Error

vite@7.3.1 – Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket (high severity)

Your Environment

21.2.5

Anything else relevant?

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions