Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39363

42
FAUCET Score

OVERVIEW CVE-2026-39363 is a file disclosure vulnerability affecting Vite, a popular frontend build tool and development server for JavaScript projects. The vulnerability exists in versions 6.0.0 through 6.4.1, 7.0.0 through 7.3.1, and 8.0.0 through 8.0.4. Attackers can exploit a WebSocket connection to the Vite dev server to read arbitrary files from the server filesystem by using the fetchModule function combined with file:// protocol handlers and query parameters like ?raw or ?inline, effectively bypassing intended access controls. SEVERITY The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a network-based attack vector, low complexity, requiring no privileges or user interaction. The impact is confidentiality-focused, allowing unauthorized disclosure of sensitive file contents such as environment variables, source code, and configuration files. The attack requires only network connectivity to an exposed Vite dev server without Origin header validation, making exploitation straightforward. The EPSS score of 0.023 indicates this vulnerability has lower probability of exploitation compared to most CVEs. EXPLOITATION STATUS There is no indication of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and is currently inactive on threat intelligence hot lists. However, organizations running affected Vite versions in development environments exposed to untrusted networks face potential risk. Immediate patching to versions 6.4.2, 7.3.2, or 8.0.5 is recommended, particularly for internet-facing dev servers.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0.0, <= 6.4.1CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
>= 7.0.0, <= 7.3.1CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
>= 8.0.0, <= 8.0.4CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
<= 0.1.15CPE matchmatch criteria
cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
3.32%
Probability of exploitation in next 30 days
EPSS Percentile
87.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-39363 · Apr 7, 2026
This CVE's current EPSS score of 0.0332 is in the 77th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

npmpatch availablevia ghsa
Product: viteFixed in: 8.0.5
npmpatch availablevia ghsa
Product: viteFixed in: 7.3.2
npmpatch availablevia ghsa
Product: viteFixed in: 6.4.2
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-p9ff-h696-f583high

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

Apr 6, 2026

References

access.redhat.com / errata/RHSA-2026:24761
access.redhat.com / errata/RHSA-2026:24762
access.redhat.com / errata/RHSA-2026:24866
access.redhat.com / security/cve/CVE-2026-39363
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-39363.json
github.com / vitejs/vite/security/advisories/GHSA-p9ff-h696-f583
ExploitVendor Advisory