Vite · Security

VITE0010Do not expose every env variable

Avoid envPrefix: "" in Vite config.

Why it happens

Vite rejects an empty envPrefix to prevent exposing every environment variable to bundled client code, including secrets.

Fix

Remove empty env prefix, or move it to the Vite runtime/API that owns that behavior.

Example

Do not expose every env var

Before

export default defineConfig({
  envPrefix: '',
})

After

export default defineConfig({
  envPrefix: 'VITE_',
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm vite-doctor . --framework vite --rules vite/env/no-empty-env-prefix
Copyright © 2026