Junglewise Threat Intelligence

CVE-2026-41211: vite-plus path traversal in downloadPackageManager()

CVE-2026-41211 · Severity: low · CVSS 3.1 · Published 2026-04-16

Technologies: Voidzero Vite-Plus. Vendors: npm.

Executive brief

Vite+ is a unified development toolchain that manages runtimes, package managers, and frontend tools. A vulnerability in the downloadPackageManager() function allows code running in the same Node.js process to escape the package cache directory and write arbitrary files to other locations on the filesystem. This could be exploited to overwrite critical files or inject malicious executables, though normal command-line usage is protected by input validation.

Technical details

The vulnerability is a path traversal (CWE-22) in the downloadPackageManager() function exported from vite-plus/binding. The function accepts a version parameter and uses it directly to construct filesystem paths under VP_HOME/package_manager/<pm>/ without validating that it is a proper semantic version. An attacker can supply path traversal sequences like ../../../escaped to escape the cache root. After download and extraction, the function deletes any pre-existing directory at the computed target, extracts the package, and writes executable shim files—all at the attacker-controlled location outside VP_HOME. The CLI itself is protected because it validates versions via semver::Version::parse() before calling this code, but direct programmatic callers to the binding export can pass untrusted input. Exploitation requires the attacker to already be executing code in the same Node.js process and influence downloadPackageManager() input; no known real-world exploitation has been reported. The vulnerability is fixed in version 0.1.17.

Affected products

  • voidzero vite-plus <= 0.1.16

Timeline

  • 2026-04-16: disclosed: GHSA-33r3-4whc-44c2 published
  • 2026-04-16: patched: Fix released in version 0.1.17

References

Related threats