Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-33r3-4whc-44c2 | Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME |
Wed, 29 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Voidzero
Voidzero vite\+ |
|
| CPEs | cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Voidzero
Voidzero vite\+ |
|
| Metrics |
cvssV3_1
|
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Voidzero-dev
Voidzero-dev vite-plus |
|
| Vendors & Products |
Voidzero-dev
Voidzero-dev vite-plus |
Thu, 23 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch. | |
| Title | `vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME` | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-23T12:32:17.823Z
Reserved: 2026-04-18T02:51:52.975Z
Link: CVE-2026-41211
Updated: 2026-04-23T12:32:07.490Z
Status : Analyzed
Published: 2026-04-23T02:16:18.860
Modified: 2026-04-29T15:49:45.557
Link: CVE-2026-41211
No data.
OpenCVE Enrichment
Updated: 2026-04-28T15:15:34Z
Github GHSA