MEDIUM🇬🇧 English

CVE-2026-39365

CVSS 6.3v4.0pub. 2026-04-07upd. 2026-07-24

Vite to framework do toolingu frontend'owego dla JavaScript. W wersjach od 6.0.0 do przed 6.4.2, 7.3.2 i 8.0.5, serwer dev nieprawidłowo obsługuje żądania .map dla zoptymalizowanych zależności — rozwiązuje ścieżki plików i wywołuje readFile bez ograniczenia segmentów ../ w URL-u. W rezultacie możliwe jest pominięcie listy dozwolonych adresów server.fs.strict i pobranie plików .map znajdujących się poza root'em projektu, o ile mogą być parsowane jako prawidłowy JSON source map. Podatność została naprawiona w wersjach 6.4.2, 7.3.2 i 8.0.5.

Pokaż oryginał (EN)

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Vitejs Vite

    APP
    Vitejs
    6.0.0 – 6.4.17.0.0 – 7.3.18.0.0 – 8.0.4
  • Voidzero Vite\+

    APP
    Voidzero
    ≤ 0.1.15
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Path Traversal
CWE
Referencje

Powiązane podatności

CVE-2026-53571HIGH8.2ten sam produkt

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files ...

CVE-2026-41211HIGH8.4ten sam produkt

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageMan...

CVE-2026-39363HIGH8.2ten sam produkt

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is po...

CVE-2026-39364HIGH8.2ten sam produkt

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev ser...

CVE-2024-23331HIGH7.5ten sam produkt

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypass...