CVE-2026-53571Patch(microsoft / vite)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft vite systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw are treated as allowed paths, while Windows resolves them to the original file's default data stream. Similar to that, Windows allows accessing a file using a different name with the 8.3 short name compatibility feature. Vite did not reject accessing files via them. This vulnerability is fixed in 8.0.16, 7.3.5, and 6.4.3.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vite
  • vite\+
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
vitevite\+windows

1 version affected across 3 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-26: 1Mentions · 2026-06-30: 1PoC Mentioned / Linked · 2026-06-30: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-30: 106-2606-30
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-261
Patch1
2026-06-301
Disclosure1
Full discourse2 posts
  • Schalk Neethling@scriptquiz
    Disclosure

    CVE-2026-53571 - GitHub Advisory Database | vite: `server.fs.deny` bypass on Windows alternate paths | https://github.com/advisories/GHSA-fx2h-pf6j-xcff

    Post summary

    The GitHub Advisory for CVE‑2026‑53571 documents a `server.fs.deny` bypass on Windows alternate paths in Vite, providing a technical overview but no patch or active exploitation details.

    0000040
    8 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 CRITICAL: CVE-2026-53571 — Vite Path Traversal on Windows CVSS 8.2. NTFS ADS bypass allows attackers to read .env files via /.env::$DATA?raw. Affects Vite ≤ 8.0.15 / 7.3.4 / 6.4.2. Patch to 8.0.16 / 7.3.5 / 6.4.3. 🔗 https://threataft.com/articles/cve-2026-53571-vite-path-traversal-windows-env-exposure #CyberSecurity #vitejs

    Post summary

    The post announces CVE-2026-53571, a path traversal flaw in Vite on Windows, provides patch information, and technical details of the vulnerability, but does not present a PoC, exploit code, or evidence of active exploitation.

    0000053
    31 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Appvitejsvite-node.js-
Appvoidzerovite\+-node.js-

Explore more