/Vulnerability Library

Vite Dev Server - Arbitrary File Read

CVE-2026-39363
Verified

Description

Vite dev server exposes the fetchModule method via its WebSocket HMR (Hot Module Replacement) endpoint using the vite-hmr sub-protocol. By connecting to the WebSocket endpoint and sending a crafted vite:invoke custom event that calls fetchModule with a file:// URL (e.g., file:///etc/passwd?raw), an attacker can bypass server.fs.deny restrictions and read arbitrary files from the server filesystem. The vulnerability exists because fetchModule does not enforce the same filesystem access controls as other Vite server endpoints.

Severity

High

CVSS Score

8.2

Exploit Probability

3%

Published Date

April 7, 2026

Template Author

theamanrawat

CVE-2026-39363.yaml
8.2Score

CVSS Metrics

CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2026-39363

References

https://github.com/advisories/GHSA-p9ff-h696-f583https://github.com/vitejs/vite/security/advisories/GHSA-p9ff-h696-f583

Remediation Steps

Upgrade Vite to a patched version: 8.0.5, 7.3.2, or 6.4.2 or later. Do not expose the Vite dev server to untrusted networks. Avoid using --host 0.0.0.0 in production or on public-facing interfaces.