{"schema_version":1,"title":"Vite vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 27 vulnerabilities in Vite: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-53632, was published on 22 June 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/vite","json_url":"https://junglewise.ai/threats/vendors/vite.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/vite","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":7,"all_time":27,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":13},"latest":[{"cve":"CVE-2026-53632","cvss":4,"epss":0.0041,"slug":"cve-2026-53632-vitejs-launch-editor-ntlm-hash-disclosure-via-unc-path-handling","title":"Vitejs launch-editor NTLM hash disclosure via UNC path handling","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:44.827+00:00","url":"https://junglewise.ai/threats/cve-2026-53632-vitejs-launch-editor-ntlm-hash-disclosure-via-unc-path-handling"},{"cve":"CVE-2026-53571","cvss":3.1,"epss":0.0058,"slug":"cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via","title":"Vite path traversal and sensitive file disclosure on Windows via NTFS ADS","severity":"high","exploited":false,"published_at":"2026-06-22T18:16:44.667+00:00","url":"https://junglewise.ai/threats/cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via"},{"cve":"CVE-2024-52011","cvss":4,"epss":0.0051,"slug":"cve-2024-52011-vite-launch-editor-command-injection-on-windows","title":"Vite launch-editor command injection on Windows","severity":"high","exploited":false,"published_at":"2026-06-01T19:16:18.977+00:00","url":"https://junglewise.ai/threats/cve-2024-52011-vite-launch-editor-command-injection-on-windows"},{"cvss":7.5,"slug":"vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-a9674fa5","title":"Vite @vitejs/plugin-rsc denial of service in React Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:36+00:00","url":"https://junglewise.ai/threats/vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-a9674fa5"},{"cvss":7.5,"slug":"next-js-and-react-denial-of-service-in-server-components-b02b7bc4","title":"Next.js and React denial of service in Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:27+00:00","url":"https://junglewise.ai/threats/next-js-and-react-denial-of-service-in-server-components-b02b7bc4"},{"cve":"CVE-2026-23870","cvss":7.5,"epss":0.0153,"slug":"cve-2026-23870-facebook-react-denial-of-service-in-react-server-components","title":"Facebook React Denial of Service in React Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:07+00:00","url":"https://junglewise.ai/threats/cve-2026-23870-facebook-react-denial-of-service-in-react-server-components"},{"cvss":7.5,"slug":"vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-2c7b66ca","title":"Vite @vitejs/plugin-rsc Denial of Service in React Server Components","severity":"high","exploited":false,"published_at":"2026-04-10T15:36:00+00:00","url":"https://junglewise.ai/threats/vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-2c7b66ca"},{"cve":"CVE-2026-39365","cvss":5.3,"epss":0.0098,"slug":"cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling","title":"Vite path traversal in optimized dependency map handling","severity":"medium","exploited":false,"published_at":"2026-04-07T20:16:30.35+00:00","url":"https://junglewise.ai/threats/cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling"},{"cve":"CVE-2026-39363","cvss":7.5,"epss":0.0262,"slug":"cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket","title":"Vite arbitrary file read via dev server WebSocket","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:30+00:00","url":"https://junglewise.ai/threats/cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket"},{"cvss":3.1,"slug":"vite-plugin-react-source-code-exposure-in-server-components-88776524","title":"Vite Plugin React source code exposure in Server Components","severity":"low","exploited":false,"published_at":"2025-12-12T16:41:58+00:00","url":"https://junglewise.ai/threats/vite-plugin-react-source-code-exposure-in-server-components-88776524"},{"cvss":3.1,"slug":"vite-plugin-react-denial-of-service-in-react-server-components-8f1b9330","title":"Vite Plugin React denial of service in React Server Components","severity":"low","exploited":false,"published_at":"2025-12-12T16:41:08+00:00","url":"https://junglewise.ai/threats/vite-plugin-react-denial-of-service-in-react-server-components-8f1b9330"},{"cvss":3.1,"slug":"react-server-components-remote-code-execution-via-deserialization-daaaee75","title":"React Server Components remote code execution via deserialization","severity":"low","exploited":false,"published_at":"2025-12-03T19:07:52+00:00","url":"https://junglewise.ai/threats/react-server-components-remote-code-execution-via-deserialization-daaaee75"},{"cve":"CVE-2025-62522","cvss":4,"epss":0.0105,"slug":"cve-2025-62522-vite-server-fs-deny-bypass-via-backslash-on-windows","title":"Vite server.fs.deny bypass via backslash on Windows","severity":"medium","exploited":false,"published_at":"2025-10-20T19:54:28+00:00","url":"https://junglewise.ai/threats/cve-2025-62522-vite-server-fs-deny-bypass-via-backslash-on-windows"},{"cve":"CVE-2025-58751","cvss":4,"epss":0.0121,"slug":"cve-2025-58751-vite-path-traversal-in-public-directory-middleware","title":"Vite path traversal in public directory middleware","severity":"medium","exploited":false,"published_at":"2025-09-09T20:55:56+00:00","url":"https://junglewise.ai/threats/cve-2025-58751-vite-path-traversal-in-public-directory-middleware"},{"cve":"CVE-2025-58752","cvss":4,"epss":0.0061,"slug":"cve-2025-58752-vite-authorization-bypass-in-html-file-serving","title":"Vite authorization bypass in HTML file serving","severity":"medium","exploited":false,"published_at":"2025-09-09T20:54:42+00:00","url":"https://junglewise.ai/threats/cve-2025-58752-vite-authorization-bypass-in-html-file-serving"},{"cve":"CVE-2025-46565","cvss":4,"epss":0.0116,"slug":"cve-2025-46565-vite-server-fs-deny-bypass-with-path-traversal","title":"Vite server.fs.deny bypass with /. path traversal","severity":"medium","exploited":false,"published_at":"2025-04-30T17:40:27+00:00","url":"https://junglewise.ai/threats/cve-2025-46565-vite-server-fs-deny-bypass-with-path-traversal"},{"cve":"CVE-2025-32395","cvss":4,"slug":"cve-2025-32395-vite-server-fs-deny-bypass-via-invalid-request-target","title":"Vite server.fs.deny bypass via invalid request-target","severity":"medium","exploited":false,"published_at":"2025-04-11T14:06:03+00:00","url":"https://junglewise.ai/threats/cve-2025-32395-vite-server-fs-deny-bypass-via-invalid-request-target"},{"cve":"CVE-2025-31486","cvss":3.1,"epss":0.4046,"slug":"cve-2025-31486-vite-server-fs-deny-bypass-via-svg-and-relative-paths","title":"Vite server.fs.deny bypass via .svg and relative paths","severity":"low","exploited":false,"published_at":"2025-04-04T14:20:05+00:00","url":"https://junglewise.ai/threats/cve-2025-31486-vite-server-fs-deny-bypass-via-svg-and-relative-paths"},{"cve":"CVE-2025-31125","cvss":3.1,"epss":0.6469,"slug":"cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server","title":"Vite server.fs.deny bypass with inline and raw query parameters","severity":"critical","exploited":true,"published_at":"2025-03-31T17:31:54+00:00","url":"https://junglewise.ai/threats/cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server"},{"cve":"CVE-2025-30208","cvss":3.1,"epss":0.7477,"slug":"cve-2025-30208-vite-access-control-bypass-in-server-fs-deny-with-query","title":"Vite access control bypass in server.fs.deny with query parameters","severity":"low","exploited":false,"published_at":"2025-03-25T14:00:02+00:00","url":"https://junglewise.ai/threats/cve-2025-30208-vite-access-control-bypass-in-server-fs-deny-with-query"},{"cve":"CVE-2025-24010","cvss":3.1,"epss":0.0029,"slug":"cve-2025-24010-vite-development-server-cors-and-websocket-origin-validation","title":"Vite development server CORS and WebSocket origin validation bypass","severity":"low","exploited":false,"published_at":"2025-01-21T19:52:55+00:00","url":"https://junglewise.ai/threats/cve-2025-24010-vite-development-server-cors-and-websocket-origin-validation"},{"cve":"CVE-2024-45812","cvss":3.1,"epss":0.0064,"slug":"cve-2024-45812-vite-dom-clobbering-gadget-leads-to-xss-in-bundled-scripts","title":"Vite DOM Clobbering gadget leads to XSS in bundled scripts","severity":"low","exploited":false,"published_at":"2024-09-17T19:28:01+00:00","url":"https://junglewise.ai/threats/cve-2024-45812-vite-dom-clobbering-gadget-leads-to-xss-in-bundled-scripts"},{"cve":"CVE-2024-45811","cvss":3.1,"epss":0.011,"slug":"cve-2024-45811-vite-server-fs-deny-bypass-via-import-raw-query-parameter","title":"Vite server.fs.deny bypass via ?import&raw query parameter","severity":"low","exploited":false,"published_at":"2024-09-17T18:44:12+00:00","url":"https://junglewise.ai/threats/cve-2024-45811-vite-server-fs-deny-bypass-via-import-raw-query-parameter"},{"cve":"CVE-2024-31207","cvss":3.1,"epss":0.0071,"slug":"cve-2024-31207-vite-server-fs-deny-bypass-with-directory-patterns","title":"Vite server.fs.deny bypass with directory patterns","severity":"low","exploited":false,"published_at":"2024-04-03T16:46:17+00:00","url":"https://junglewise.ai/threats/cve-2024-31207-vite-server-fs-deny-bypass-with-directory-patterns"},{"cve":"CVE-2024-23331","cvss":3.1,"epss":0.0079,"slug":"cve-2024-23331-vite-dev-server-fs-deny-bypass-via-case-insensitive-filesystem","title":"Vite dev server fs.deny bypass via case-insensitive filesystem","severity":"low","exploited":false,"published_at":"2024-01-19T21:58:47+00:00","url":"https://junglewise.ai/threats/cve-2024-23331-vite-dev-server-fs-deny-bypass-via-case-insensitive-filesystem"}],"vendor":{"hub":true,"name":"Vite","slug":"vite","homepage":"https://vitejs.dev/","description":"The maintainers of the Vite frontend build tool ecosystem.","url":"https://junglewise.ai/threats/vendors/vite"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-31125","cvss":3.1,"epss":0.6469,"slug":"cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server","title":"Vite server.fs.deny bypass with inline and raw query parameters","severity":"critical","exploited":true,"published_at":"2025-03-31T17:31:54+00:00","url":"https://junglewise.ai/threats/cve-2025-31125-vitejs-vite-improper-access-control-in-dev-server"},{"cve":"CVE-2026-39363","cvss":7.5,"epss":0.0262,"slug":"cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket","title":"Vite arbitrary file read via dev server WebSocket","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:30+00:00","url":"https://junglewise.ai/threats/cve-2026-39363-vite-arbitrary-file-read-via-dev-server-websocket"},{"cve":"CVE-2026-23870","cvss":7.5,"epss":0.0153,"slug":"cve-2026-23870-facebook-react-denial-of-service-in-react-server-components","title":"Facebook React Denial of Service in React Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:07+00:00","url":"https://junglewise.ai/threats/cve-2026-23870-facebook-react-denial-of-service-in-react-server-components"},{"cvss":7.5,"slug":"vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-a9674fa5","title":"Vite @vitejs/plugin-rsc denial of service in React Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:36+00:00","url":"https://junglewise.ai/threats/vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-a9674fa5"},{"cvss":7.5,"slug":"next-js-and-react-denial-of-service-in-server-components-b02b7bc4","title":"Next.js and React denial of service in Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:27+00:00","url":"https://junglewise.ai/threats/next-js-and-react-denial-of-service-in-server-components-b02b7bc4"},{"cvss":7.5,"slug":"vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-2c7b66ca","title":"Vite @vitejs/plugin-rsc Denial of Service in React Server Components","severity":"high","exploited":false,"published_at":"2026-04-10T15:36:00+00:00","url":"https://junglewise.ai/threats/vite-vitejs-plugin-rsc-denial-of-service-in-react-server-components-2c7b66ca"},{"cve":"CVE-2024-52011","cvss":4,"epss":0.0051,"slug":"cve-2024-52011-vite-launch-editor-command-injection-on-windows","title":"Vite launch-editor command injection on Windows","severity":"high","exploited":false,"published_at":"2026-06-01T19:16:18.977+00:00","url":"https://junglewise.ai/threats/cve-2024-52011-vite-launch-editor-command-injection-on-windows"},{"cve":"CVE-2026-53571","cvss":3.1,"epss":0.0058,"slug":"cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via","title":"Vite path traversal and sensitive file disclosure on Windows via NTFS ADS","severity":"high","exploited":false,"published_at":"2026-06-22T18:16:44.667+00:00","url":"https://junglewise.ai/threats/cve-2026-53571-vite-path-traversal-and-sensitive-file-disclosure-on-windows-via"},{"cve":"CVE-2026-39365","cvss":5.3,"epss":0.0098,"slug":"cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling","title":"Vite path traversal in optimized dependency map handling","severity":"medium","exploited":false,"published_at":"2026-04-07T20:16:30.35+00:00","url":"https://junglewise.ai/threats/cve-2026-39365-vite-path-traversal-in-optimized-dependency-map-handling"},{"cve":"CVE-2025-58751","cvss":4,"epss":0.0121,"slug":"cve-2025-58751-vite-path-traversal-in-public-directory-middleware","title":"Vite path traversal in public directory middleware","severity":"medium","exploited":false,"published_at":"2025-09-09T20:55:56+00:00","url":"https://junglewise.ai/threats/cve-2025-58751-vite-path-traversal-in-public-directory-middleware"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[{"name":"Vite","slug":"vite","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/vite"},{"name":"Vite Plugin-Rsc","slug":"plugin-rsc","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/plugin-rsc"}]}