Vite · VITE0016

Avoid broad Vite server.fs.allow entries

Keep Vite dev server filesystem allow lists scoped to project paths.
VITE0016vite-doctor/vitesecuritywarnNo fix

Run this rule

pnpm vite-doctor . --framework vite --rules vite/server/no-broad-fs-allow

Why it matters

Vite configuration runs in both dev and build pipelines. Narrow, explicit settings reduce surprises across SSR, workers, and local file access.

Remove broad fs allow, or move it to the Vite runtime/API that owns that behavior.

Example

Limit server.fs.allow

Before

export default defineConfig({
  server: {
    fs: { allow: ['..'] },
  },
})

After

export default defineConfig({
  server: {
    fs: { allow: ['packages/ui'] },
  },
})
Copyright © 2026