logo

Frontend Secrets Exposed: Vite Patches Critical Security Bypass in Dev Server

ID: d1bf1098-22ff-5334-9349-ab1062fae584

STIX ID: report--d1bf1098-22ff-5334-9349-ab1062fae584

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Vite dev servers are affected by two critical vulnerabilities (CVE-2026-39364 and CVE-2026-39363) that let an attacker read sensitive files: one bypasses server.fs.deny via crafted query parameters to retrieve files like .env, and the other abuses the HMR WebSocket fetchModule path to read arbitrary file:// paths. The report lists affected 6.x–8.x Vite releases and Vite-Plus, describes exposure conditions (network-hosted dev servers and active WebSockets), and urges immediate upgrades to the provided patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.