vitejs/vite · error · Error

envPrefix option contains value '', which could lead…

Error message

envPrefix option contains value '', which could lead unexpected exposure of sensitive information.

What it means

resolveEnvPrefix validates the envPrefix option. An empty-string prefix matches every env variable, leaking secrets (DATABASE_PASSWORD, API_KEY, etc.) into client bundle code via import.meta.env. Vite refuses to start if envPrefix contains ''. The check runs after arraify so both '' and ['VITE_', ''] trigger it.

Solutions

  1. List explicit prefixes, e.g. envPrefix: ['VITE_', 'APP_'].
  2. Use the default 'VITE_' prefix and rename the variables you need exposed.
  3. If you genuinely need to expose a sensitive variable, do it through define with an explicit allow-list.

Example fix

// before
export default defineConfig({ envPrefix: '' })
// after
export default defineConfig({ envPrefix: ['VITE_', 'APP_'] })
Defensive patterns

Strategy: validation

Validate before calling

function validateEnvPrefix(prefix) {
  const arr = Array.isArray(prefix) ? prefix : [prefix];
  if (arr.includes('')) return 'envPrefix must not include empty string';
  return null;
}

Type guard

function hasNoEmptyPrefix(prefix) {
  const arr = Array.isArray(prefix) ? prefix : [prefix];
  return arr.every((p) => p !== '');
}

Prevention

When it happens

Trigger: Setting envPrefix: '' (or including '' in the array) in vite.config, intending to expose all env vars to the client.

Common situations: Developers who want every env var available client-side without listing prefixes; misconfigured monorepo presets that default envPrefix to an empty string; copy-pasting configs that use '' to mean 'all'.

Related errors


AI-assisted analysis of vitejs/vite@b4d66fee14 (2026-08-11). Data as JSON: /api/errors/adf787f3256a2df1. Report an issue: GitHub.

Appendix: source

Thrown at packages/vite/src/node/env.ts:114

  // check if there are actual env variables starting with VITE_*
  // these are typically provided inline and should be prioritized
  for (const key in process.env) {
    if (prefixes.some((prefix) => key.startsWith(prefix))) {
      env[key] = process.env[key]!
    }
  }

  debug?.(`using resolved env: %O`, env)

  return env
}

export function resolveEnvPrefix({
  envPrefix = 'VITE_',
}: UserConfig): string[] {
  envPrefix = arraify(envPrefix)
  if (envPrefix.includes('')) {
    throw new Error(
      `envPrefix option contains value '', which could lead unexpected exposure of sensitive information.`,
    )
  }
  if (envPrefix.some((prefix) => /\s/.test(prefix))) {
    // eslint-disable-next-line no-console
    console.warn(
      colors.yellow(
        `[vite] Warning: envPrefix option contains values with whitespace, which does not work in practice.`,
      ),
    )
  }
  return envPrefix
}

View on GitHub (pinned to b4d66fee14)