vite vulnerabilities
CVEs whose affected-version data names the vite package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-53571HighPoCvite: `server.fs.deny` bypass on Windows alternate paths
vite: `server.fs.deny` bypass on Windows alternate paths
CVE-2026-53632Mediumlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
CVE-2026-39364High· 7.5PoCVite is a frontend tooling framework for JavaScript
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query par…
CVE-2026-39363High· 7.5PoCVite is a frontend tooling framework for JavaScript
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…