VYPR
`), it ","datePublished":"2023-12-04T23:15:27.73Z","dateModified":"2026-06-17T06:35:47.193Z","publisher":{"@type":"Organization","@id":"https://portal.vyprsec.ai#publisher","name":"VYPR","url":"https://portal.vyprsec.ai","logo":{"@type":"ImageObject","url":"https://portal.vyprsec.ai/icon.svg","width":64,"height":64},"description":"Real-time CVE intelligence newsroom — feeds, exploits, vendor advisories, and AI-synthesized insights."},"author":{"@type":"Organization","@id":"https://portal.vyprsec.ai#publisher","name":"VYPR","url":"https://portal.vyprsec.ai","logo":{"@type":"ImageObject","url":"https://portal.vyprsec.ai/icon.svg","width":64,"height":64},"description":"Real-time CVE intelligence newsroom — feeds, exploits, vendor advisories, and AI-synthesized insights."},"proficiencyLevel":"Expert","about":{"@type":"Thing","@id":"https://nvd.nist.gov/vuln/detail/CVE-2023-49293","name":"CVE-2023-49293","identifier":"CVE-2023-49293","description":"Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (``), it is possible to inject arbitrary HTML into the transformed output by supplying a malicious URL query string to `server.transformIndexHtml`. Only apps using `appType: 'custom'` and using the default Vite HTML middleware are affected. The HTML entry must also contain an inline script. The attack requires a user to click on a malicious URL while running the dev server. Restricted files aren't exposed to the attacker. This issue has been addressed in [email protected], [email protected], and [email protected]. There are no known workarounds for this vulnerability.","additionalType":"https://schema.org/SoftwareApplication","sameAs":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49293"]},"keywords":"CVE-2023-49293, Medium, CWE-79, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite, Vitejs Vite","mentions":[{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}},{"@type":"SoftwareApplication","name":"Vite","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Vitejs"}}],"isAccessibleForFree":true},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://portal.vyprsec.ai/"},{"@type":"ListItem","position":2,"name":"CVEs","item":"https://portal.vyprsec.ai/cves"},{"@type":"ListItem","position":3,"name":"CVE-2023-49293","item":"https://portal.vyprsec.ai/cves/CVE-2023-49293"}]}]}
Medium severity6.1NVD Advisory· Published Dec 4, 2023· Updated Jun 17, 2026

CVE-2023-49293

CVE-2023-49293

Description

Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via server.transformIndexHtml, the original request URL is passed in unmodified, and the html being transformed contains inline module scripts (`), it is possible to inject arbitrary HTML into the transformed output by supplying a malicious URL query string to server.transformIndexHtml. Only apps using appType: 'custom'` and using the default Vite HTML middleware are affected. The HTML entry must also contain an inline script. The attack requires a user to click on a malicious URL while running the dev server. Restricted files aren't exposed to the attacker. This issue has been addressed in [email protected], [email protected], and [email protected]. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
vitenpm
>= 4.4.0, < 4.4.124.4.12
vitenpm
>= 4.5.0, < 4.5.14.5.1
vitenpm
>= 5.0.0, < 5.0.55.0.5

Affected products

25
  • Vitejs/Vite24 versions
    cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*+ 23 more
    • cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*range: >=4.4.0,<=4.4.11
    • cpe:2.3:a:vitejs:vite:5.0.0:-:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta0:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta10:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta11:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta12:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta13:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta14:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta15:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta16:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta17:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta18:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta19:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta1:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta20:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta2:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta3:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta4:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta5:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta6:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta7:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta8:*:*:*:node.js:*:*
    • cpe:2.3:a:vitejs:vite:5.0.0:beta9:*:*:*:node.js:*:*
    • (no CPE)range: >=4.4.0, < 4.4.12
  • ghsa-coords
    Range: >= 4.4.0, < 4.4.12

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.