Vite Dev Server Chained Access-Control Bypass Exploitation Success (CVE-2025-30208/CVE-2025-31125/CVE-2024-45811)
Detects successful exploitation attempts targeting Vite development servers via chained access-control bypass vulnerabilities (CVE-2025-30208, CVE-2025-31125, CVE-2024-45811). The rule identifies malicious GET requests using the /@fs/ endpoint with specific query parameters, resulting in a successful HTTP 200 response, while originating from non-internal IP addresses.
Suricata

