CVE-2026-39364 is an authentication bypass vulnerability affecting Vite, a popular frontend build tool framework for JavaScript. The vulnerability exists in versions 7.1.0 through 7.3.1 and 8.0.0 through 8.0.4, allowing attackers to bypass the server.fs.deny file access restrictions on the development server. By appending query parameters such as ?raw, ?import&raw, or ?import&url&inline to requests, an attacker can retrieve sensitive files including environment configurations (.env) and certificates (*.crt) that should be blocked. The vulnerability has been remediated in versions 7.3.2 and 8.0.5. The vulnerability carries a CVSS 3.1 severity rating of 7.5 (HIGH), indicating significant risk. It requires no authentication or user interaction and can be exploited remotely with low complexity over a network. The attack results in high confidentiality impact through unauthorized information disclosure, though it does not affect system integrity or availability. The EPSS score of 0.036 places this vulnerability in the lower percentile of exploit probability compared to similar CVEs. There is currently no evidence of active exploitation in the wild or public exploit code availability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and community attention appears limited. Organizations using affected Vite versions should prioritize updating to patched releases, particularly those whose development environments handle sensitive configuration files or certificates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, <= 7.3.1CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 8.0.0, <= 8.0.4CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
<= 0.1.15CPE matchmatch criteria | cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.