CVE-2026-39363
high
CVSS v3
7.5
CVSS v2
—
VIR risk
7.5
Description
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security-advisories@github.com — https://github.com/vitejs/vite/security/advisories/GHSA-p9ff-h696-f583
References
- https://github.com/vitejs/vite/security/advisories/GHSA-p9ff-h696-f583
- https://nvd.nist.gov/vuln/detail/CVE-2026-39363
- https://github.com/vitejs/vite/pull/22159
- https://github.com/vitejs/vite/commit/f02d9fde0b195afe3ea2944414186962fbbe41e0
- https://github.com/vitejs/vite
- https://github.com/vitejs/vite/releases/tag/v6.4.2
- https://github.com/vitejs/vite/releases/tag/v7.3.2
- https://github.com/vitejs/vite/releases/tag/v8.0.5
CWEs
CWE-200 CWE-306
Verify integrity in audit chain (admin only). AS-IS.