Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-31125 PoC — Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

Source
Associated Vulnerability
Title: Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query (CVE-2025-31125)
Description:Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
Description
Vite 任意文件读取漏洞POC
Readme
# CVE-2025-31125 漏洞检测工具

这是一个用于检测 CVE-2025-31125 漏洞的 Python 脚本工具。

## 作者信息

- Author: 大智
- Date: 2025-04-01

## 功能特点

- 支持单个目标检测
- 支持批量目标检测
- 自动保存检测结果
- 彩色输出界面
- 详细的检测日志

## 环境要求

- Python 3.6 或更高版本
- Windows/Linux/MacOS 操作系统

## 快速开始

### 1. 安装依赖

```bash
# 一键安装所需依赖
pip install -r requirements.txt
```

### 2. 使用方法

#### 方式一:检测单个目标

```bash
python main.py http://example.com
```

#### 方式二:批量检测目标

1. 创建 `ips.txt` 文件,每行一个目标地址,例如:
```
http://example1.com
http://example2.com
http://example3.com
```

2. 运行脚本:
```bash
python main.py
```

### 3. 输出结果

- 检测结果将保存在 `result.txt` 文件中
- 详细日志将保存在 `full_log.json` 文件中

## 注意事项

- 请确保您有权限对目标系统进行检测
- 建议在测试环境中使用
- 使用前请仔细阅读相关法律法规

## 免责声明

本工具仅用于安全研究和授权测试,请勿用于非法用途。使用本工具进行任何未经授权的测试所造成的后果由使用者自行承担。

## 更新日志

- 2025-04-01: 首次发布 
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →