Skip to main content

Vendor/product archive

voidzero / vite+ CVEs

Beta · best-effort

5 CVEs tagged to voidzero / vite+0 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-41211

Published Apr 23, 2026

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39365

Published Apr 7, 2026

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves f…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39364

Published Apr 7, 2026

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.cr…

CVSS 8.2 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-39363

Published Apr 7, 2026

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origi…

CVSS 8.2 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1