CVE-2026-39363Disclosure(vitejs / vite)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vitejs vite systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default "..."). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-306CWE-1220

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vite
  • vite\+

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-07); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
vitevite\+

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-07: 1Mentions · 2026-04-09: 1Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-17: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-17: 104-0704-0904-17
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-091
Patch1
2026-04-171
Disclosure1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    Vite patches critical flaws (CVE-2026-39364 & CVE-2026-39363) allowing arbitrary file reads and .env leaks via WebSockets and query params. Upgrade to 8.0.5! #ViteJS #CyberSecurity #InfoSec #WebDev #Vulnerability #HMR #Frontend #JavaScript https://securityonline.info/vite-vulnerabilities-cve-2026-39364-arbitrary-file-read/ https://t.co/qakJVmhUYt

    Post summary

    The post announces that Vite’s critical CVEs have been patched in version 8.0.5, providing technical details of the vulnerabilities but no PoC or active exploitation evidence.

    01064472
    12.3K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-39363 - high 🚨 Vite Dev Server - Arbitrary File Read > Vite dev server exposes the fetchModule method via its WebSocket HMR (Hot Module Repl... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-39363 @pdnuclei #NucleiTemplates #cve

    Post summary

    A new CVE-2026-39363 affecting Vite Dev Server, causing an arbitrary file read via the fetchModule WebSocket HMR, has been disclosed with technical details and a linked resource for more information.

    00012166
    930 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39363 Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket wit… https://www.cve.org/CVERecord?id=CVE-2026-39363

    Post summary

    The post notes the existence of CVE-2026-39363 but supplies no PoC, exploit, or mitigation details, indicating a brief disclosure.

    0000075
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appvitejsvite-node.js-
Appvoidzerovite\+-node.js-

Explore more