Skip to content

bug: Windows paths containing ~ trigger false "outside of Vite serving allow list" errors #22892

Description

@tanmay-haldar0

Describe the bug

Reproduction repository

A minimal reproduction is available here:

https://github.com/tanmay-haldar0/vite-path-tilde-repro

To reproduce:

  1. Clone the repository.
  2. Place it in a directory containing ~, for example:
    D:\code\test~\vite-path-tilde-repro
    
  3. Run:
    npm install
    npm run dev
  4. Open the local Vite URL.

Reproduction

https://github.com/tanmay-haldar0/vite-path-tilde-repro

Steps to reproduce

  1. Create a new Vite project.
npm create vite@latest vite-app
cd vite-app
npm install
  1. Move the project into a Windows directory whose path contains the ~ character.

Example:

D:\code\test~\vite-app
  1. Start the development server.
npm run dev
  1. Open the local development URL shown by Vite (for example, http://localhost:5173/).

  2. Observe that Vite responds with:

403 Restricted

The request url ".../index.html" is outside of Vite serving allow list.
  1. Move the same project to a path without ~.

Example:

D:\code\vite-app
  1. Run:
npm run dev
  1. Open the same URL again. The application loads normally.

System Info

System:
    OS: Windows 11 10.0.26200
    CPU: (12) x64 AMD Ryzen 5 5500GT with Radeon Graphics
    Memory: 2.46 GB / 7.37 GB
  Binaries:
    Node: 24.18.0 - C:\Program Files\nodejs\node.EXE
    npm: 11.16.0 - C:\Program Files\nodejs\npm.CMD
  Browsers:
    Chrome: 150.0.7871.47
    Edge: Chromium (150.0.4078.48)

Used Package Manager

npm

Logs

Click to expand!
PS D:\code\test~\vite-path-tilde-repro> npx vite --debug

vite:config bundled config file loaded in XXms
vite:env loading env files:
vite:env   D:/code/test~/vite-path-tilde-repro/.env
vite:env   D:/code/test~/vite-path-tilde-repro/.env.local
vite:env   D:/code/test~/vite-path-tilde-repro/.env.development
vite:env   D:/code/test~/vite-path-tilde-repro/.env.development.local
vite:env env files loaded in Xms
vite:config using resolved config:
{
  ...
  root: 'D:/code/test~/vite-path-tilde-repro',
  ...
  server: {
    fs: {
      strict: true,
      allow: [
        'D:/code/test~/vite-path-tilde-repro'
      ]
    }
  }
  ...
}

VITE v8.1.3 ready in XXX ms

➜  Local:   http://localhost:5173/
➜  Network: use --host to expose

The request url "D:/code/test~/vite-path-tilde-repro/index.html" is outside of Vite serving allow list.

- D:/code/test~/vite-path-tilde-repro

Refer to docs https://vite.dev/config/server-options.html#server-fs-allow for configurations and more details.

Validations

Activity

  1. tanmay-haldar0 commented on Jul 8, 2026

    @tanmay-haldar0
    Author

    vite_tilde_fix.zip Man, that tilde thing in the path totally messes with the vite allow list logic on Windows. I found that it's just a regex mismatch in the middleware during path normalization. I attached a patch that handles the special character properly.

    This is a malware do not misguide people.

    here is the file report:
    https://www.virustotal.com/gui/file/d85d164e46fabb085609f2586e8fec364539a6ec81f74659f0cb28ac76e7880b
    here is the details:
    https://www.virustotal.com/gui/file/d85d164e46fabb085609f2586e8fec364539a6ec81f74659f0cb28ac76e7880b/details

  2. Lukenickerson commented on Jul 16, 2026

    @Lukenickerson

    I encountered this bug also. I get the error with 8.1.4, but not with 8.0.0.
    The issue appears to be caused by this commit: dc245c7

  3. added
    p2-edge-caseBug, but has workaround or limited in scope (priority)
    and removed on Aug 18, 2026
  4. locked and limited conversation to collaborators on Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    p2-edge-caseBug, but has workaround or limited in scope (priority)

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions