Junglewise Threat Intelligence

CVE-2026-53632: Vitejs launch-editor NTLM hash disclosure via UNC path handling

CVE-2026-53632 · Severity: medium · CVSS 4 · Published 2026-06-22

Technologies: Vite, vite-plus (npm). Vendors: Vite, npm.

Executive brief

The launch-editor library, commonly used in development tools like Vite to open files in a code editor, contains a flaw that can leak Windows user credentials. If a developer visits a malicious website while their development server is running, the attacker can force the developer's computer to connect to a rogue server. This connection automatically sends the user's encrypted password (NTLMv2 hash), which the attacker can then attempt to crack to gain full access to the developer's account or internal corporate systems.

Technical details

The launch-editor package prior to version 2.14.1 accepts arbitrary file paths, including Windows Universal Naming Convention (UNC) paths, without proper validation. When a Windows system attempts to access a UNC path (e.g., \\attacker-host\share), the OS automatically initiates NTLM authentication, transmitting the user's NTLMv2 hash to the remote host. An attacker can exploit this by sending a crafted request to a development server's middleware (such as Vite's __open-in-editor endpoint) that uses the vulnerable library. If the attacker controls the destination SMB server, they can capture the hash for offline cracking. This vulnerability is fixed in launch-editor 2.14.1 and corresponding updates for Vite.

Affected products

  • vitejs launch-editor < 2.14.1
  • vitejs vite >= 8.0.0, < 8.0.16; >= 7.0.0, < 7.3.5; < 6.4.3
  • vitejs vite-plus < 0.1.24

Timeline

  • 2026-06-01: advisory: GitHub Security Advisory published
  • 2026-06-22: disclosed: CVE published to NVD

References

Related threats