← Zurück zur CVE-Suche

CVE-2026-39363

Vite

Beschreibung

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server-s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default -...-). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

CVSS 7.5EPSS 3.319%Risiko 0.97
Quelle öffnen
Veröffentlicht
2026-04-07 20:16:30
Betroffene Versionen
>=6.0.0,<6.4.2,>=7.0.0,<7.3.2,>=8.0.0,<8.0.5
Typ
Package
Zuletzt geändert
2026-08-04 13:18:24
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N