<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T15:44:37.939594+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253112</id>
    <title>EUVD-2026-253112</title>
    <updated>2026-10-07T15:44:37.942972+00:00</updated>
    <content>EUVD-2026-253112</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59427</id>
    <title>fkie_cve-2025-59427</title>
    <updated>2026-10-07T15:44:37.943012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars. This vulnerability is fixed in 1.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4pfg-2mw5-f8jx</id>
    <title>GHSA-4pfg-2mw5-f8jx — Cloudflare Vite plugin exposes secrets over the built-in dev server</title>
    <updated>2026-10-07T15:44:37.943057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @cloudflare/vite-plugin</p>
<p>### Summary</p>
<p>Note: [originally posted on H1](https://hackerone.com/reports/3117837) but closed. Cross-posting over to here in abundance of caution instead of a public issue.</p>
<p>When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as:
- `.env`
- `.dev.vars`</p>
<p>### PoC
1. Create a Workers project that utilises the `@cloudflare/vite-plugin`. For example:
   - `npm create cloudflare@latest` - select Framework Starter -&gt; React
2. Add any secret files to test if they're accessible. `echo foobar=secret &gt; .dev.vars` for example
3. Run `npm run dev` to start the dev server (after running `npm ci` if necessary to install dependencies) and then hit the following to expose information:</p>
<p>`curl http://localhost:5173/.env` may expose any secrets in this file
`curl http://localhost:5173/.dev.vars` may expose any secrets in this file
`curl http://localhost:5173/package.json` may expose dependencies used by the project, potentially leading to other vulnerabilities
`curl http://localhost:5173/README.md` may expose internal documentation</p>
<p>### Impact</p>
<p>If the vite dev server is exposed on a public network, such as when a user simply uses `wrangler` to serve their application and doesn't publish to Cloudflare in production, an attacker may be able to acquire secrets that the user doesn't wish to be exposed.</p>
<p>Another common scenario where this could happen is wh…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4pfg-2mw5-f8jx"/>
  </entry>
</feed>
