Summary
When vp create targets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.
The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.
Reproduction
-
Create a directory containing a sentinel file:
mkdir linked-directory
printf 'keep\n' > linked-directory/keep.txt
-
Create a target directory symlink:
ln -s "$PWD/linked-directory" new-project
-
Start any vp create flow with new-project as its target directory.
-
When prompted, select “Remove existing files and continue”.
-
Check the linked directory:
test -e linked-directory/keep.txt
Actual behavior
linked-directory/keep.txt is deleted. Other entries in the linked directory are also removed recursively, except for the existing .git preservation behavior.
Expected behavior
The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.
It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.
Impact
This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.
The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.
Environment
- Reproduced on macOS arm64
- Node.js v25.9.0
- Vite+ revision:
295c8d6069605a249ed39e8c5e4d4d3d79e4be3e
A draft fix is available in #2418.
Summary
When
vp createtargets a non-empty directory symbolic link, choosing “Remove existing files and continue” deletes files inside the linked directory instead of removing or rejecting the link itself.The confirmation prompt only displays the target path. It does not indicate that deletion will occur in the directory referenced by that path.
Reproduction
Create a directory containing a sentinel file:
Create a target directory symlink:
ln -s "$PWD/linked-directory" new-projectStart any
vp createflow withnew-projectas its target directory.When prompted, select “Remove existing files and continue”.
Check the linked directory:
test -e linked-directory/keep.txtActual behavior
linked-directory/keep.txtis deleted. Other entries in the linked directory are also removed recursively, except for the existing.gitpreservation behavior.Expected behavior
The overwrite flow should not implicitly traverse the final target symlink and delete its destination contents.
It should treat the symbolic link as a distinct filesystem entry, or otherwise make the resolved deletion target explicit before performing a destructive operation.
Impact
This can cause irreversible local data loss outside the symbolic-link entry shown by the prompt.
The trigger is limited: the create target must be a symbolic link and the user must confirm removal. This is therefore a low-frequency but high-impact local data-loss issue, not a remote security vulnerability.
Environment
295c8d6069605a249ed39e8c5e4d4d3d79e4be3eA draft fix is available in #2418.