Vite dev server could allow reading files from the Vite project root by bypassing server.fs.deny with double forward-slash paths (//). This affects exposed dev servers only.
id: CVE-2023-34092
info:
name: Vite Dev Server - Information Exposure
author: ritikchaddha
se
...