Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [cve] ยท confidence: medium ยท severity: high ยท affected_sectors: [global] ยท au_impact: false

NVD description: From 7.1.0 to before 7.3.2 and 8.0.5, files that server.fs.deny should block โ€” .env, *.crt and similar โ€” can be retrieved with HTTP 200 responses when crafted query parameters are appended to the request.

The operation exploits CVE-2026-39364, a high-severity flaw that bypasses file read and access controls in Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5, disclosed on 7 April.

Attribute Detail
CVE CVE-2026-39364
CVSS 7.5 (High)
Vendor / product Vite (frontend tooling framework for JavaScript)
Reported 2026-09-16