{"schema_version":1,"title":"Vite vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in Vite: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-53632, was published on 22 June 2026.","url":"https://junglewise.ai/threats/technologies/vite","json_url":"https://junglewise.ai/threats/technologies/vite.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/vite","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":22,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":7},"latest":[{"cve":"CVE-2026-53632","cvss":4,"epss":0.0041,"slug":"cve-2026-53632-vitejs-launch-editor-ntlm-hash-disclosure-via-unc-path-handling","title":"Vitejs launch-editor NTLM hash disclosure via UNC path handling","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:44.827+00:00","url":"https://junglewise.ai/threats/cve-2026-53632-vitejs-launch-editor-ntlm-hash-disclosure-via-unc-path-handling"},{"cve":"CVE-2026-53571","cvss":3.1,"epss":0.0058,"slug":"cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via","title":"Vite path traversal and sensitive file disclosure on Windows via NTFS ADS","severity":"high","exploited":false,"published_at":"2026-06-22T18:16:44.667+00:00","url":"https://junglewise.ai/threats/cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via"},{"cve":"CVE-2024-52011","cvss":4,"epss":0.0051,"slug":"cve-2024-52011-vite-launch-editor-command-injection-on-windows","title":"Vite launch-editor command injection on Windows","severity":"high","exploited":false,"published_at":"2026-06-01T19:16:18.977+00:00","url":"https://junglewise.ai/threats/cve-2024-52011-vite-launch-editor-command-injection-on-windows"},{"cve":"CVE-2026-39365","cvss":5.3,"epss":0.0098,"slug":"cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling","title":"Vite path traversal in optimized dependency map handling","severity":"medium","exploited":false,"published_at":"2026-04-07T20:16:30.35+00:00","url":"https://junglewise.ai/threats/cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling"},{"cve":"CVE-2026-39364","cvss":7.5,"epss":0.0154,"slug":"cve-2026-39364-vite-information-disclosure-via-query-parameter-manipulation-in","title":"Vite information disclosure via query parameter manipulation in dev server","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:30.17+00:00","url":"https://junglewise.ai/threats/cve-2026-39364-vite-information-disclosure-via-query-parameter-manipulation-in"},{"cve":"CVE-2026-39363","cvss":7.5,"epss":0.0262,"slug":"cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket","title":"Vite arbitrary file read via dev server WebSocket","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:30+00:00","url":"https://junglewise.ai/threats/cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket"},{"cve":"CVE-2025-62522","cvss":4,"epss":0.0105,"slug":"cve-2025-62522-vite-server-fs-deny-bypass-via-backslash-on-windows","title":"Vite server.fs.deny bypass via backslash on Windows","severity":"medium","exploited":false,"published_at":"2025-10-20T19:54:28+00:00","url":"https://junglewise.ai/threats/cve-2025-62522-vite-server-fs-deny-bypass-via-backslash-on-windows"},{"cve":"CVE-2025-58751","cvss":4,"epss":0.0121,"slug":"cve-2025-58751-vite-path-traversal-in-public-directory-middleware","title":"Vite path traversal in public directory middleware","severity":"medium","exploited":false,"published_at":"2025-09-09T20:55:56+00:00","url":"https://junglewise.ai/threats/cve-2025-58751-vite-path-traversal-in-public-directory-middleware"},{"cve":"CVE-2025-58752","cvss":4,"epss":0.0061,"slug":"cve-2025-58752-vite-authorization-bypass-in-html-file-serving","title":"Vite authorization bypass in HTML file serving","severity":"medium","exploited":false,"published_at":"2025-09-09T20:54:42+00:00","url":"https://junglewise.ai/threats/cve-2025-58752-vite-authorization-bypass-in-html-file-serving"},{"cve":"CVE-2025-46565","cvss":4,"epss":0.0116,"slug":"cve-2025-46565-vite-server-fs-deny-bypass-with-path-traversal","title":"Vite server.fs.deny bypass with /. path traversal","severity":"medium","exploited":false,"published_at":"2025-04-30T17:40:27+00:00","url":"https://junglewise.ai/threats/cve-2025-46565-vite-server-fs-deny-bypass-with-path-traversal"},{"cve":"CVE-2025-32395","cvss":4,"slug":"cve-2025-32395-vite-server-fs-deny-bypass-via-invalid-request-target","title":"Vite server.fs.deny bypass via invalid request-target","severity":"medium","exploited":false,"published_at":"2025-04-11T14:06:03+00:00","url":"https://junglewise.ai/threats/cve-2025-32395-vite-server-fs-deny-bypass-via-invalid-request-target"},{"cve":"CVE-2025-31486","cvss":3.1,"epss":0.4046,"slug":"cve-2025-31486-vite-server-fs-deny-bypass-via-svg-and-relative-paths","title":"Vite server.fs.deny bypass via .svg and relative paths","severity":"low","exploited":false,"published_at":"2025-04-04T14:20:05+00:00","url":"https://junglewise.ai/threats/cve-2025-31486-vite-server-fs-deny-bypass-via-svg-and-relative-paths"},{"cve":"CVE-2025-31125","cvss":3.1,"epss":0.6469,"slug":"cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server","title":"Vite server.fs.deny bypass with inline and raw query parameters","severity":"critical","exploited":true,"published_at":"2025-03-31T17:31:54+00:00","url":"https://junglewise.ai/threats/cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server"},{"cve":"CVE-2025-30208","cvss":3.1,"epss":0.7477,"slug":"cve-2025-30208-vite-access-control-bypass-in-server-fs-deny-with-query","title":"Vite access control bypass in server.fs.deny with query parameters","severity":"low","exploited":false,"published_at":"2025-03-25T14:00:02+00:00","url":"https://junglewise.ai/threats/cve-2025-30208-vite-access-control-bypass-in-server-fs-deny-with-query"},{"cve":"CVE-2025-24010","cvss":3.1,"epss":0.0029,"slug":"cve-2025-24010-vite-development-server-cors-and-websocket-origin-validation","title":"Vite development server CORS and WebSocket origin validation bypass","severity":"low","exploited":false,"published_at":"2025-01-21T19:52:55+00:00","url":"https://junglewise.ai/threats/cve-2025-24010-vite-development-server-cors-and-websocket-origin-validation"},{"cve":"CVE-2024-45812","cvss":3.1,"epss":0.0064,"slug":"cve-2024-45812-vite-dom-clobbering-gadget-leads-to-xss-in-bundled-scripts","title":"Vite DOM Clobbering gadget leads to XSS in bundled scripts","severity":"low","exploited":false,"published_at":"2024-09-17T19:28:01+00:00","url":"https://junglewise.ai/threats/cve-2024-45812-vite-dom-clobbering-gadget-leads-to-xss-in-bundled-scripts"},{"cve":"CVE-2024-45811","cvss":3.1,"epss":0.011,"slug":"cve-2024-45811-vite-server-fs-deny-bypass-via-import-raw-query-parameter","title":"Vite server.fs.deny bypass via ?import&raw query parameter","severity":"low","exploited":false,"published_at":"2024-09-17T18:44:12+00:00","url":"https://junglewise.ai/threats/cve-2024-45811-vite-server-fs-deny-bypass-via-import-raw-query-parameter"},{"cve":"CVE-2024-31207","cvss":3.1,"epss":0.0071,"slug":"cve-2024-31207-vite-server-fs-deny-bypass-with-directory-patterns","title":"Vite server.fs.deny bypass with directory patterns","severity":"low","exploited":false,"published_at":"2024-04-03T16:46:17+00:00","url":"https://junglewise.ai/threats/cve-2024-31207-vite-server-fs-deny-bypass-with-directory-patterns"},{"cve":"CVE-2024-23331","cvss":3.1,"epss":0.0079,"slug":"cve-2024-23331-vite-dev-server-fs-deny-bypass-via-case-insensitive-filesystem","title":"Vite dev server fs.deny bypass via case-insensitive filesystem","severity":"low","exploited":false,"published_at":"2024-01-19T21:58:47+00:00","url":"https://junglewise.ai/threats/cve-2024-23331-vite-dev-server-fs-deny-bypass-via-case-insensitive-filesystem"},{"cve":"CVE-2023-49293","cvss":3.1,"epss":0.01,"slug":"cve-2023-49293-vite-xss-vulnerability-in-server-transformindexhtml-via-url","title":"Vite XSS vulnerability in server.transformIndexHtml via URL payload","severity":"low","exploited":false,"published_at":"2023-12-05T23:31:34+00:00","url":"https://junglewise.ai/threats/cve-2023-49293-vite-xss-vulnerability-in-server-transformindexhtml-via-url"},{"cve":"CVE-2023-34092","cvss":3.1,"slug":"cve-2023-34092-vite-security-bypass-in-server-fs-deny-via-double-forward-slash","title":"Vite security bypass in server.fs.deny via double forward-slash","severity":"low","exploited":false,"published_at":"2023-06-06T02:01:39+00:00","url":"https://junglewise.ai/threats/cve-2023-34092-vite-security-bypass-in-server-fs-deny-via-double-forward-slash"},{"cve":"CVE-2022-35204","cvss":3.1,"epss":0.0127,"slug":"cve-2022-35204-vite-directory-traversal-via-url-encoding-bypass","title":"Vite directory traversal via URL encoding bypass","severity":"low","exploited":false,"published_at":"2022-08-19T00:00:20+00:00","url":"https://junglewise.ai/threats/cve-2022-35204-vite-directory-traversal-via-url-encoding-bypass"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Vite Plugin-Rsc","slug":"plugin-rsc","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/plugin-rsc"}],"technology":{"hub":true,"name":"Vite","slug":"vite","vendor":{"name":"Vite","slug":"vite","url":"https://junglewise.ai/threats/vendors/vite"},"aliases":[],"category":"framework","homepage":"https://vitejs.dev","repo_url":"https://github.com/vitejs/vite","description":"A build tool and dev server for modern JavaScript applications.","url":"https://junglewise.ai/threats/technologies/vite"},"most_severe":[{"cve":"CVE-2025-31125","cvss":3.1,"epss":0.6469,"slug":"cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server","title":"Vite server.fs.deny bypass with inline and raw query parameters","severity":"critical","exploited":true,"published_at":"2025-03-31T17:31:54+00:00","url":"https://junglewise.ai/threats/cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server"},{"cve":"CVE-2026-39363","cvss":7.5,"epss":0.0262,"slug":"cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket","title":"Vite arbitrary file read via dev server WebSocket","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:30+00:00","url":"https://junglewise.ai/threats/cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket"},{"cve":"CVE-2026-39364","cvss":7.5,"epss":0.0154,"slug":"cve-2026-39364-vite-information-disclosure-via-query-parameter-manipulation-in","title":"Vite information disclosure via query parameter manipulation in dev server","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:30.17+00:00","url":"https://junglewise.ai/threats/cve-2026-39364-vite-information-disclosure-via-query-parameter-manipulation-in"},{"cve":"CVE-2024-52011","cvss":4,"epss":0.0051,"slug":"cve-2024-52011-vite-launch-editor-command-injection-on-windows","title":"Vite launch-editor command injection on Windows","severity":"high","exploited":false,"published_at":"2026-06-01T19:16:18.977+00:00","url":"https://junglewise.ai/threats/cve-2024-52011-vite-launch-editor-command-injection-on-windows"},{"cve":"CVE-2026-53571","cvss":3.1,"epss":0.0058,"slug":"cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via","title":"Vite path traversal and sensitive file disclosure on Windows via NTFS ADS","severity":"high","exploited":false,"published_at":"2026-06-22T18:16:44.667+00:00","url":"https://junglewise.ai/threats/cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via"},{"cve":"CVE-2026-39365","cvss":5.3,"epss":0.0098,"slug":"cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling","title":"Vite path traversal in optimized dependency map handling","severity":"medium","exploited":false,"published_at":"2026-04-07T20:16:30.35+00:00","url":"https://junglewise.ai/threats/cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling"},{"cve":"CVE-2025-58751","cvss":4,"epss":0.0121,"slug":"cve-2025-58751-vite-path-traversal-in-public-directory-middleware","title":"Vite path traversal in public directory middleware","severity":"medium","exploited":false,"published_at":"2025-09-09T20:55:56+00:00","url":"https://junglewise.ai/threats/cve-2025-58751-vite-path-traversal-in-public-directory-middleware"},{"cve":"CVE-2025-46565","cvss":4,"epss":0.0116,"slug":"cve-2025-46565-vite-server-fs-deny-bypass-with-path-traversal","title":"Vite server.fs.deny bypass with /. path traversal","severity":"medium","exploited":false,"published_at":"2025-04-30T17:40:27+00:00","url":"https://junglewise.ai/threats/cve-2025-46565-vite-server-fs-deny-bypass-with-path-traversal"},{"cve":"CVE-2025-62522","cvss":4,"epss":0.0105,"slug":"cve-2025-62522-vite-server-fs-deny-bypass-via-backslash-on-windows","title":"Vite server.fs.deny bypass via backslash on Windows","severity":"medium","exploited":false,"published_at":"2025-10-20T19:54:28+00:00","url":"https://junglewise.ai/threats/cve-2025-62522-vite-server-fs-deny-bypass-via-backslash-on-windows"},{"cve":"CVE-2025-58752","cvss":4,"epss":0.0061,"slug":"cve-2025-58752-vite-authorization-bypass-in-html-file-serving","title":"Vite authorization bypass in HTML file serving","severity":"medium","exploited":false,"published_at":"2025-09-09T20:54:42+00:00","url":"https://junglewise.ai/threats/cve-2025-58752-vite-authorization-bypass-in-html-file-serving"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}