CVE detail
CVE-2026-39363
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default "..."). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39363.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 7, 2026, 8:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2456179bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 7, 2026, 8:16 PM - https://access.redhat.com/security/cve/CVE-2026-39363access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:24866access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:24762access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:24761access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 7, 2026, 8:16 PM No excerpt available.
Exploitgithub.comApr 7, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-53571CVSS 8.2 · High
Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser o…
- CVE-2026-61267CVSS 7.3 · High
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.…
- CVE-2026-61233CVSS 9.8 · Critical
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily…
- CVE-2026-61175CVSS 9.3 · Critical
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily…
- CVE-2026-60705CVSS 7.0 · High
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Difficult t…
- CVE-2026-53647CVSS 6.9 · Medium
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without aut…