CVE-2026-39365 is a path traversal vulnerability affecting Vite, a popular JavaScript frontend build tool, in versions 6.0.0 through 6.4.1, 7.0.0 through 7.3.1, and 8.0.0 through 8.0.4. The vulnerability exists in the development server's handling of .map file requests, where insufficient path validation allows attackers to use ../ directory traversal sequences to bypass the server.fs.strict allow list and read source map files outside the project root. The vulnerability carries a CVSS 3.1 severity score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. However, successful exploitation is constrained by the requirement that accessed files must be valid JSON-formatted source maps, limiting the practical scope of exposure. The attack impacts confidentiality by potentially exposing sensitive information in source maps, though integrity and availability are not affected. There are no confirmed public exploits or active exploitation campaigns documented for this vulnerability. The KEV catalog does not list it as actively exploited in the wild, and it remains relatively low in community attention with an EPSS percentile score of only 0.79%, indicating minimal real-world prevalence. Organizations should apply the available patches (6.4.2, 7.3.2, or 8.0.5) during routine maintenance cycles rather than treating this as an urgent incident.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.4.1CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 7.0.0, <= 7.3.1CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 8.0.0, <= 8.0.4CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
<= 0.1.15CPE matchmatch criteria | cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.