Vite · Security

VITE0008Avoid broad Vite env prefixes

Keep Vite client env prefixes narrow enough to avoid accidental exposure.

Why it happens

Every matching prefix exposes environment variables to client code through import.meta.env, so broad prefixes can publish unrelated configuration.

Fix

Remove broad env prefix, or move it to the Vite runtime/API that owns that behavior.

Example

Use narrow env prefixes

Before

export default defineConfig({
  envPrefix: ['VITE_', 'APP_'],
})

After

export default defineConfig({
  envPrefix: ['VITE_PUBLIC_'],
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm vite-doctor . --framework vite --rules vite/env/no-broad-env-prefix
Copyright © 2026