Package impact
npm / vite
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2026-39364 | high | 7.5 | 7.5 | 2mo ago | Vite: `server.fs.deny` bypassed with queries | |
| CVE-2026-39363 | high | 7.5 | 7.5 | 2mo ago | Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket | |
| CVE-2026-39365 | medium | 5.3 | 5.3 | 2mo ago | Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling |