Skip to content

create: overwrite follows target symlinks and deletes linked contents #2419

Description

@leslieeilsel

Summary

When vp create targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.

The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.

Reproduction

  1. Create a directory containing a sentinel file:

    mkdir linked-directory
    printf 'keep\n' > linked-directory/keep.txt
  2. Create a target directory symlink:

    ln -s "$PWD/linked-directory" new-project
  3. Start any vp create flow with new-project as its target directory.

  4. When prompted, select “Remove existing files and continue”.

  5. Check the linked directory:

    test -e linked-directory/keep.txt

Actual behavior

linked-directory/keep.txt is deleted. Other entries in the linked directory are also removed recursively, except for the existing .git preservation behavior.

Expected behavior

The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.

It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.

Impact

This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.

The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.

Environment

  • Reproduced on macOS arm64
  • Node.js v25.9.0
  • Vite+ revision: 295c8d6069605a249ed39e8c5e4d4d3d79e4be3e

A draft fix is available in #2418.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions