Vite · Security

VITE0016Avoid broad Vite server.fs.allow entries

Keep Vite dev server filesystem allow lists scoped to project paths.

Why it happens

Vite configuration runs in both dev and build pipelines. Narrow, explicit settings reduce surprises across SSR, workers, and local file access.

Fix

Remove broad fs allow, or move it to the Vite runtime/API that owns that behavior.

Example

Limit server.fs.allow

Before

export default defineConfig({
  server: {
    fs: { allow: ['..'] },
  },
})

After

export default defineConfig({
  server: {
    fs: { allow: ['packages/ui'] },
  },
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm vite-doctor . --framework vite --rules vite/server/no-broad-fs-allow
Copyright © 2026