<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Vite</title><description>Actively exploited vulnerabilities affecting Vite products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/vite.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-31125 — Vite Vitejs Improper Access Control Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-31125</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-31125</guid><description>This flaw in Vite&apos;s development server allows attackers to read files that should be inaccessible by appending specially crafted query parameters such as ?inline&amp;import or ?raw?import to requests. If your team runs Vite&apos;s dev server exposed to a network — via the --host flag or server.host configuration — arbitrary files on the host could be read by anyone who can reach that server. Production builds are not affected, but exposed dev environments present a real data-exposure risk.</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate><category>Vite</category><category>Vitejs</category></item></channel></rss>