CVE-2025-67489 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2025-67489 requires immediate attention.

· 3 min read

```html

Executive Summary

A critical vulnerability, CVE-2025-67489, has been identified in the npm package @vitejs/plugin-rsc, allowing for arbitrary remote code execution on development servers. This vulnerability arises from unsafe dynamic imports in server function APIs when integrated into React Server Components (RSC) applications. Attackers with network access can exploit this to execute arbitrary JavaScript code, leading to potential data exfiltration and unauthorized access to sensitive files.

Immediate Action

  • Immediately stop using @vitejs/plugin-rsc in development environments.
  • Isolate affected development servers from external networks.
  • Upgrade to a patched version as soon as it is available (check vendor advisories for updates).
  • Review and limit the use of vite --host to avoid exposing your server on all network interfaces.
  • Consider implementing network-level protections to restrict access to development servers.

Affected Versions

  • @vitejs/plugin-rsc@<=X.Y.Z vulnerable; upgrade to @vitejs/plugin-rsc@X.Y.Z+ (exact patch version TBD).

Resolution Guide

To mitigate this vulnerability, follow these steps:

npm install @vitejs/plugin-rsc@X.Y.Z+

For hardening your configuration, consider adding the following in your server setup:

export VITE_DISABLE_DYNAMIC_IMPORT=true

Here is a minimal patch snippet to avoid unsafe dynamic imports:

if (!isValidImport(url)) { throw new Error('Invalid import attempt'); }

Detection & Verification

To check if your project is vulnerable, run the following command:

npm list @vitejs/plugin-rsc

Verify the fix by ensuring that the installed version is updated:

npm list @vitejs/plugin-rsc

Look for the version number to confirm it is X.Y.Z+.

Risk and Impact

If exploited, this vulnerability allows attackers to execute arbitrary JavaScript code with Node.js privileges on development servers. This could lead to unauthorized access to sensitive data, including source code, environment variables, and credentials, significantly increasing the risk of further compromise across your internal services.

```

Keep reading