Vite · Security
VITE0016Avoid broad Vite server.fs.allow entries
Keep Vite dev server filesystem allow lists scoped to project paths.
vite-doctor/vitesecuritywarnNo fix
Why it happens
Vite configuration runs in both dev and build pipelines. Narrow, explicit settings reduce surprises across SSR, workers, and local file access.
Fix
Remove broad fs allow, or move it to the Vite runtime/API that owns that behavior.
Example
Limit server.fs.allow
Before
export default defineConfig({
server: {
fs: { allow: ['..'] },
},
})
After
export default defineConfig({
server: {
fs: { allow: ['packages/ui'] },
},
})
Verify the fix
Run only this rule after editing so the report stays focused on the diagnostic you are closing:
pnpm vite-doctor . --framework vite --rules vite/server/no-broad-fs-allow