Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39364

42
FAUCET Score

CVE-2026-39364 is an authentication bypass vulnerability affecting Vite, a popular frontend build tool framework for JavaScript. The vulnerability exists in versions 7.1.0 through 7.3.1 and 8.0.0 through 8.0.4, allowing attackers to bypass the server.fs.deny file access restrictions on the development server. By appending query parameters such as ?raw, ?import&raw, or ?import&url&inline to requests, an attacker can retrieve sensitive files including environment configurations (.env) and certificates (*.crt) that should be blocked. The vulnerability has been remediated in versions 7.3.2 and 8.0.5. The vulnerability carries a CVSS 3.1 severity rating of 7.5 (HIGH), indicating significant risk. It requires no authentication or user interaction and can be exploited remotely with low complexity over a network. The attack results in high confidentiality impact through unauthorized information disclosure, though it does not affect system integrity or availability. The EPSS score of 0.036 places this vulnerability in the lower percentile of exploit probability compared to similar CVEs. There is currently no evidence of active exploitation in the wild or public exploit code availability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and community attention appears limited. Organizations using affected Vite versions should prioritize updating to patched releases, particularly those whose development environments handle sensitive configuration files or certificates.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0.0, <= 7.3.1CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
>= 8.0.0, <= 8.0.4CPE matchmatch criteria
cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*
<= 0.1.15CPE matchmatch criteria
cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
2.10%
Probability of exploitation in next 30 days
EPSS Percentile
79.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-39364 · Apr 9, 2026
This CVE's current EPSS score of 0.0209 is in the 64th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

npmpatch availablevia ghsa
Product: viteFixed in: 8.0.5
npmpatch availablevia ghsa
Product: viteFixed in: 7.3.2
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-v2wj-q39q-566rhigh

Vite: `server.fs.deny` bypassed with queries

Apr 6, 2026

References

access.redhat.com / errata/RHSA-2026:24866
access.redhat.com / security/cve/CVE-2026-39364
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-39364.json
github.com / vitejs/vite/security/advisories/GHSA-v2wj-q39q-566r
ExploitVendor Advisory