Package impact

npm NPM / vite-plus

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41211 critical 10.0 10.0 1mo ago Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME