Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v2wj-q39q-566r | Vite: `server.fs.deny` bypassed with queries |
Thu, 30 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Voidzero
Voidzero vite\+ |
|
| CPEs | cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Voidzero
Voidzero vite\+ |
Wed, 15 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vitejs:vite-plus:*:*:*:*:*:node.js:*:* cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* |
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vitejs
Vitejs vite Vitejs vite-plus |
|
| Vendors & Products |
Vitejs
Vitejs vite Vitejs vite-plus |
Wed, 08 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-472 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5. | |
| Title | Vite has a `server.fs.deny` bypass with queries | |
| Weaknesses | CWE-180 CWE-284 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T20:01:56.564Z
Reserved: 2026-04-06T21:29:17.349Z
Link: CVE-2026-39364
Updated: 2026-04-07T20:01:52.997Z
Status : Analyzed
Published: 2026-04-07T20:16:30.170
Modified: 2026-04-30T18:34:57.303
Link: CVE-2026-39364
OpenCVE Enrichment
Updated: 2026-05-14T14:45:22Z
Github GHSA