← Volver al buscador de CVEs

CVE-2026-39365

Vite

Descripción

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server-s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

CVSS 5.3EPSS 0.914%Riesgo 0.57
Ver fuente
Publicación
2026-04-07 20:16:30
Versiones afectadas
>=6.0.0,<6.4.2,>=7.0.0,<7.3.2,>=8.0.0,<8.0.5
Tipo
Package
Última modificación
2026-07-24 21:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N