PatchSiren

vitejs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Vitejs CVE published 2026-06-22

CVE-2026-53571

CVE-2026-53571 is a high-severity vulnerability in Vite, a frontend tooling framework for JavaScript. The vulnerability allows the contents of sensitive files, such as .env, .env.*, and *.{crt,pem}, to be returned to the browser on Windows. This occurs because Vite's dev server does not correctly normalize NTFS ADS path forms before access checks are applied. As a result, requests like /.env::$DATA?raw ar [truncated]

HIGH vitejs CVE published 2026-06-01

CVE-2024-52011

CVE-2024-52011 is a command injection vulnerability in the launch-editor npm package, affecting versions prior to 2.9.0. The flaw exists in the `launchEditor` function's insufficient sanitization of the `file` argument on Windows systems. An attacker can execute arbitrary commands by supplying a crafted filename containing special characters. This vulnerability is particularly relevant for development env [truncated]

MEDIUM vitejs CVE published 2026-04-07

CVE-2026-39365

The CVE record for CVE-2026-39365 was published on 2026-04-07T20:16:30.350Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Vite, a frontend tooling framework for JavaScript, from version 6.0.0 to before versions 6.4.2, 7.3.2, and 8.0.5. The vulnerability class involves path traversal in the dev server's handling of .map requests for optimized dependen [truncated]

HIGH Vitejs CVE published 2026-04-07

CVE-2026-39364

CVE-2026-39364 is a high-severity vulnerability in Vite, a frontend tooling framework for JavaScript. The vulnerability allows files that should be blocked by server.fs.deny (e.g., .env, *.crt) to be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This issue affects Vite versions from 7.1.0 to before 7.3.2 and 8.0.5. The vulnerability [truncated]