Sploitus

CVE-2026-39365

No indexed exploits for CVE-2026-39365 yet

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

Affected products
Vite
Vitejs Vite
≤ 6.4.1, 7.3.1, 8.0.4
Voidzero Vite\+
≤ 0.1.15
Fix
Available
CVSS 4.0
6.3 MEDIUM
CVSS 3.1
5.3 MEDIUM
EPSS
0.9% (57th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-04-07
CVE-2026-39365 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-39365 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-39365 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.