Vite Dev Server - Arbitrary File Read
CVE-2026-39363
Verified
Description
Vite dev server exposes the fetchModule method via its WebSocket HMR (Hot Module Replacement) endpoint using the vite-hmr sub-protocol. By connecting to the WebSocket endpoint and sending a crafted vite:invoke custom event that calls fetchModule with a file:// URL (e.g., file:///etc/passwd?raw), an attacker can bypass server.fs.deny restrictions and read arbitrary files from the server filesystem. The vulnerability exists because fetchModule does not enforce the same filesystem access controls as other Vite server endpoints.
Severity
High
CVSS Score
8.2
Exploit Probability
3%
Published Date
April 7, 2026
Template Author
theamanrawat
CVE-2026-39363.yaml
8.2Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2026-39363
Remediation Steps
Upgrade Vite to a patched version: 8.0.5, 7.3.2, or 6.4.2 or later. Do not expose the Vite dev server to untrusted networks. Avoid using --host 0.0.0.0 in production or on public-facing interfaces.