/Vulnerability Library

Vite Dev Server - Directory Traversal

CVE-2026-39364
Verified

Description

Vite is a modern frontend build tool. In Vite prior to versions 6.4.3, 6.3.4, and 5.4.23, a directory traversal vulnerability affects the Vite development server. When the Vite dev server is launched with the --host or server.host option, an unauthenticated attacker can craft a request with a path containing dot segments (e.g., /.vite/../<filename>) to bypass static file restrictions and access arbitrary files on the filesystem under the project root. The vulnerability allows access to files normally denied by Vite’s "server.fs.deny" setting, including sensitive files like .env, configuration files, or credentials in the project root. This issue has been fixed in versions 6.4.3, 6.3.4, and 5.4.23.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Published Date

April 9, 2026

Template Author

ritikchaddha

CVE-2026-39364.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-39364
CWE ID:
cwe-22

References

https://github.com/vitejs/vite/security/advisories/GHSA-cw47-99h4-q43fhttps://nvd.nist.gov/vuln/detail/CVE-2026-39364

Remediation Steps

Update to versions 7.3.2 or 8.0.5 or later.