← Πίσω στην αναζήτηση CVE

CVE-2026-39363

Vite

Περιγραφή

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server-s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default -...-). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

CVSS 7.5EPSS 3.319%Κίνδυνος 0.97
Προβολή πηγής
Δημοσίευση
2026-04-07 20:16:30
Επηρεαζόμενες εκδόσεις
>=6.0.0,<6.4.2,>=7.0.0,<7.3.2,>=8.0.0,<8.0.5
Τύπος
Package
Τελευταία τροποποίηση
2026-08-04 13:18:24
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N