Junglewise Threat Intelligence

CVE-2026-39365: Vite path traversal in optimized dependency map handling

CVE-2026-39365 · Severity: medium · CVSS 5.3 · Published 2026-04-07

Technologies: vite-plus (npm), Vite. Vendors: npm, Vite.

Executive brief

Vite is a popular build tool and development server used by web developers. When the dev server is exposed to the network, an attacker can bypass security restrictions and retrieve sensitive source map files (.map) from outside the project directory by injecting path traversal sequences into source map requests. This could expose source code or other sensitive information embedded in these files.

Technical details

The vulnerability is a path traversal (CWE-22) and information disclosure (CWE-200) flaw in Vite's dev server middleware that processes .map requests for optimized dependencies. The vulnerable component resolves file paths from URLs and calls readFile without restricting ../ segments, allowing attackers to escape the project root. Attack vector is network-based and requires no authentication or user interaction, but does require two preconditions: (1) the dev server must be explicitly exposed to the network via --host or server.host configuration, and (2) sensitive .map files with predictable paths must exist outside the project. An attacker can craft requests to /@vite-optimized-deps/<relative-path>/.map with traversal sequences to read arbitrary .map files. Patches are available in versions 6.4.2, 7.3.2, and 8.0.5.

Affected products

  • Vite Vite 6.4.1 and earlier, 7.0.0 through 7.3.1, 8.0.0 through 8.0.4
  • npm vite-plus 0.1.15 and earlier

Timeline

  • 2026-04-06: disclosed: Vulnerability disclosed via GitHub Advisory GHSA-4w7w-66w2-5vf9
  • 2026-04-06: patched: Patches released: Vite 6.4.2, 7.3.2, 8.0.5

References

Related threats