\n \n\n```\n\n3. Kick off Vite \n\n```\nnpm run dev\n```\n\n4. Load the development server (open `http://localhost:5173/`) as well as the malicious page in the browser. \n5. Edit `src/App.jsx` file and intentionally place a syntax error\n6. Notice how the malicious page can view the websocket messages and a snippet of the source code is exposed\n\nHere's a video demonstrating the POC:\n\nhttps://github.com/user-attachments/assets/a4ad05cd-0b34-461c-9ff6-d7c8663d6961","datePublished":"2025-01-21","dateModified":"2026-07-10","author":{"@type":"Organization","name":"Safeguard"},"url":"https://gold.safeguard.sh/vulnerability/GHSA-vg6x-rcgg-rjx6","about":{"@type":"Thing","name":"GHSA-vg6x-rcgg-rjx6","additionalProperty":[{"@type":"PropertyValue","name":"severity","value":"medium"},{"@type":"PropertyValue","name":"cvss","value":"6.5"},{"@type":"PropertyValue","name":"fixedVersion","value":"6.0.9, 5.4.12, 4.5.6"}]}}

Loading vulnerability details...