type: cve ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [cve] ยท confidence: medium ยท severity: high ยท affected_sectors: [global] ยท au_impact: false
NVD description: From 7.1.0 to before 7.3.2 and 8.0.5, files that server.fs.deny should block โ .env, *.crt and similar โ can be retrieved with HTTP 200 responses when crafted query parameters are appended to the request.
The operation exploits CVE-2026-39364, a high-severity flaw that bypasses file read and access controls in Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5, disclosed on 7 April.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-39364 |
| CVSS | 7.5 (High) |
| Vendor / product | Vite (frontend tooling framework for JavaScript) |
| Reported | 2026-09-16 |