Vite · VITE0009

Do not read secret-looking env vars in client code

Flags client secret pattern in Vite env code before it leaks into runtime behavior.
VITE0009vite-doctor/vitesecurityerrorNo fix
vite/env/no-client-secret-patternsrc/rule-packs/vite/rules/env.ts Upstream docs

Run this rule

pnpm vite-doctor . --framework vite --rules vite/env/no-client-secret-pattern

Why it matters

Secrets that reach public runtime config or client bundles can be exposed to every visitor and crawler.

Remove client secret pattern, or move it to the Vite runtime/API that owns that behavior.

Example

Keep secret env vars server-only

Before

const token = import.meta.env.VITE_API_SECRET

After

const apiBase = import.meta.env.VITE_PUBLIC_API_BASE
Copyright © 2026