CVE-2026-39365
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.
- Affected products
- Vite
- Vitejs Vite
- ≤ 6.4.1, 7.3.1, 8.0.4
- Voidzero Vite\+
- ≤ 0.1.15
- Fix
- Available
- CVSS 4.0
- 6.3 MEDIUM
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2026-04-07
CVE-2026-39365 at NVD
No indexed exploits for CVE-2026-39365 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-39365 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.