Skip to main content
QUIETLYTIC
Vulnerability

Vite Path Traversal (CVE-2026-39364)

CVE-2026-39364 is a CVSS 7.5 file-restriction bypass in the Vite dev server, reported exploited by VulnCheck alone.

CVE-2026-39364
Threat Level
HIGH
CVSS
7.5
Status
Active Exploitation
Confidence
Medium
Affected Products
Vite (7.1.0 before 7.3.2, before 8.0.5)

CVE-2026-39364 carries a CVSS 3.1 base score of 7.5 against Vite, a widely used frontend build-tooling framework for JavaScript. NVD classifies it under CWE-180, CWE-284, and CWE-472 (canonicalization/access-control ordering issues), and states the flaw is fixed in versions 7.3.2 and 8.0.5, affecting versions from 7.1.0 up to those fixes. VulnCheck’s KEV feed reports the CVE as exploited, dated September 11, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-39364 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description states Vite’s development server enforces a deny-list (server.fs.deny) intended to block requests for sensitive files such as .env files and TLS private keys. NVD states that deny-list check runs before certain internal module-transform query modifiers are applied, so a request carrying one of those modifiers alongside a path to an otherwise-blocked file can reach Vite’s file-serving code with an HTTP 200 response instead of being rejected — the access check validates the request before the path is fully resolved, rather than after.

We are deliberately not reproducing the specific query modifiers NVD’s description identifies as triggering the bypass, since Vite’s dev server is widely run during local development and CI, and publishing the exact working values would function as a directly usable exploitation instruction rather than vulnerability reporting; readers needing that detail for authorized testing or patch verification should consult the linked vendor security advisory.

Evidence and confidence

  • Medium confidence — the CVSS 7.5 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the CWE-180/CWE-284/CWE-472 classification, the affected version range, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by Vite’s own GitHub security advisory. The exploitation report traces to VulnCheck KEV alone.
  • High exploitation probability — FIRST’s EPSS model scores this CVE at 0.01996, a 79.7th percentile score as of our ingestion — notably high for a VulnCheck-only listing, and consistent with how widely deployed Vite’s dev server is across the JavaScript ecosystem.

No field is in conflict between our two sources.

Why this matters

Vite’s dev server is meant to be a local-only development tool, but it’s frequently exposed on shared networks (a developer binding it to 0.0.0.0 for testing on another device, a CI runner, or a containerized dev environment reachable from adjacent infrastructure), and .env files sitting next to a project’s source code routinely contain API keys, database credentials, and other secrets. An unauthenticated bypass of the exact protection meant to stop that class of exposure is a meaningful risk anywhere a Vite dev server instance is reachable beyond the developer’s own machine.

Frequently Asked Questions

What is CVE-2026-39364? A CVSS 7.5 access-control ordering vulnerability (CWE-180/CWE-284/CWE-472) in the Vite dev server, versions 7.1.0 up to 7.3.2 and up to 8.0.5, allowing certain query-parameter-modified requests to bypass the server.fs.deny file-access restriction and retrieve blocked files such as .env files.

Is CVE-2026-39364 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 11, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. The CVSS vector confirms this is exploitable without authentication or user interaction against any reachable Vite dev server instance.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which versions fix this? Versions 7.3.2 and 8.0.5, per NVD and Vite’s own GitHub security advisory.


Severity, vector, weakness classification, affected versions, and mechanism sourced from the National Vulnerability Database record for CVE-2026-39364, corroborated by Vite’s own GitHub security advisory. Exploitation status and the September 11, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools