All 2 CVE vulnerabilities found in vite-plugin-react, with AI-generated Chinese analysis, references, and POCs.
Vendor: vitejs
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-68155 | @vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Development CWE-22 | 7.5 | High | 2025-12-16 |
| CVE-2025-67489 | @vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server CWE-94 | 9.8 | Critical | 2025-12-09 |
All 2 known CVE vulnerabilities affecting vite-plugin-react with full Chinese analysis, references, and POCs where available.