vite-plus vulnerabilities
CVEs whose affected-version data names the vite-plus package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-53571HighPoCvite: `server.fs.deny` bypass on Windows alternate paths
vite: `server.fs.deny` bypass on Windows alternate paths
▾ Midnightvite · viteEPSS 0.58%via GHSA
CVE-2026-53632Mediumlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
▾ Sunlitlaunch-editor · launch-editorEPSS 0.43%via GHSA
CVE-2026-53633Critical· 9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
▾ Midnightvitest · @vitest/browserEPSS 0.90%via GHSA