{"record":{"id":"adf787f3256a2df1","repo":"vitejs/vite","slug":"envprefix-option-contains-value-which-could-le","errorCode":null,"errorMessage":"envPrefix option contains value '', which could lead unexpected exposure of sensitive information.","messagePattern":"envPrefix option contains value '', which could lead unexpected exposure of sensitive information\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/vite/src/node/env.ts","lineNumber":114,"sourceCode":"  // check if there are actual env variables starting with VITE_*\n  // these are typically provided inline and should be prioritized\n  for (const key in process.env) {\n    if (prefixes.some((prefix) => key.startsWith(prefix))) {\n      env[key] = process.env[key]!\n    }\n  }\n\n  debug?.(`using resolved env: %O`, env)\n\n  return env\n}\n\nexport function resolveEnvPrefix({\n  envPrefix = 'VITE_',\n}: UserConfig): string[] {\n  envPrefix = arraify(envPrefix)\n  if (envPrefix.includes('')) {\n    throw new Error(\n      `envPrefix option contains value '', which could lead unexpected exposure of sensitive information.`,\n    )\n  }\n  if (envPrefix.some((prefix) => /\\s/.test(prefix))) {\n    // eslint-disable-next-line no-console\n    console.warn(\n      colors.yellow(\n        `[vite] Warning: envPrefix option contains values with whitespace, which does not work in practice.`,\n      ),\n    )\n  }\n  return envPrefix\n}\n","sourceCodeStart":96,"sourceCodeEnd":128,"githubUrl":"https://github.com/vitejs/vite/blob/b4d66fee14d970f45b8a6f3d7d6aee73ca9b88ab/packages/vite/src/node/env.ts#L96-L128","documentation":"resolveEnvPrefix validates the envPrefix option. An empty-string prefix matches every env variable, leaking secrets (DATABASE_PASSWORD, API_KEY, etc.) into client bundle code via import.meta.env. Vite refuses to start if envPrefix contains ''. The check runs after arraify so both '' and ['VITE_', ''] trigger it.","triggerScenarios":"Setting envPrefix: '' (or including '' in the array) in vite.config, intending to expose all env vars to the client.","commonSituations":"Developers who want every env var available client-side without listing prefixes; misconfigured monorepo presets that default envPrefix to an empty string; copy-pasting configs that use '' to mean 'all'.","solutions":["List explicit prefixes, e.g. envPrefix: ['VITE_', 'APP_'].","Use the default 'VITE_' prefix and rename the variables you need exposed.","If you genuinely need to expose a sensitive variable, do it through define with an explicit allow-list."],"exampleFix":"// before\nexport default defineConfig({ envPrefix: '' })\n// after\nexport default defineConfig({ envPrefix: ['VITE_', 'APP_'] })","handlingStrategy":"validation","validationCode":"function validateEnvPrefix(prefix) {\n  const arr = Array.isArray(prefix) ? prefix : [prefix];\n  if (arr.includes('')) return 'envPrefix must not include empty string';\n  return null;\n}","typeGuard":"function hasNoEmptyPrefix(prefix) {\n  const arr = Array.isArray(prefix) ? prefix : [prefix];\n  return arr.every((p) => p !== '');\n}","tryCatchPattern":null,"preventionTips":["Always use at least one non-empty prefix (default 'VITE_').","Audit envPrefix in shared configs to avoid accidental '' from spreads."],"tags":["env","security","config","env-prefix"],"backgroundTag":null,"analyzedSha":"b4d66fee14d970f45b8a6f3d7d6aee73ca9b88ab","analyzedAt":"2026-08-11T11:49:19.515Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}