Voidzero's vulnerability profile centers on its Vite build tool, a widely adopted development dependency that processes and serves frontend assets. The durable signal is a cluster of path-traversal, information-disclosure, and access-control weaknesses that arise from file-system and request-handling logic, reflecting the exposure inherent to a development server that bridges local and network contexts. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Voidzero over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39364HIGH Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-39363HIGH Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-53571HIGH Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on | Jun 22, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-41211CRITICAL Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in | Apr 23, 2026 | 10.0 | 31 | NO | NO |
CVE-2026-39365MEDIUM Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves fi | Apr 7, 2026 | 5.3 | 31 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Voidzero.
Media articles that mention a CVE ID that affects a product developed by Voidzero — matched by CVE ID, not by vendor name.