OVERVIEW CVE-2026-39363 is a file disclosure vulnerability affecting Vite, a popular frontend build tool and development server for JavaScript projects. The vulnerability exists in versions 6.0.0 through 6.4.1, 7.0.0 through 7.3.1, and 8.0.0 through 8.0.4. Attackers can exploit a WebSocket connection to the Vite dev server to read arbitrary files from the server filesystem by using the fetchModule function combined with file:// protocol handlers and query parameters like ?raw or ?inline, effectively bypassing intended access controls. SEVERITY The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a network-based attack vector, low complexity, requiring no privileges or user interaction. The impact is confidentiality-focused, allowing unauthorized disclosure of sensitive file contents such as environment variables, source code, and configuration files. The attack requires only network connectivity to an exposed Vite dev server without Origin header validation, making exploitation straightforward. The EPSS score of 0.023 indicates this vulnerability has lower probability of exploitation compared to most CVEs. EXPLOITATION STATUS There is no indication of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and is currently inactive on threat intelligence hot lists. However, organizations running affected Vite versions in development environments exposed to untrusted networks face potential risk. Immediate patching to versions 6.4.2, 7.3.2, or 8.0.5 is recommended, particularly for internet-facing dev servers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.4.1CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 7.0.0, <= 7.3.1CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 8.0.0, <= 8.0.4CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
<= 0.1.15CPE matchmatch criteria | cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.