Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39363

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default "..."). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

A flaw was found in Vite, a frontend tooling framework. A remote attacker can exploit this vulnerability by connecting to the Vite development server's WebSocket without an Origin header. This allows the attacker to invoke the fetchModule function, enabling them to retrieve the contents of arbitrary files on the server. This information disclosure can lead to unauthorized access to sensitive data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 4rhacs-eng/release-mainNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Affected
Red Hat Ansible Automation Platform 2automation-controllerWill not fix
Red Hat Ansible Automation Platform 2automation-eda-controllerNot affected
Red Hat Build of KeycloakviteWill not fix
Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Affected
Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Affected
Red Hat Build of Podman Desktop - Tech Previewredhat-user-workloads/bootc-extAffected
Red Hat Build of Podman Desktop - Tech Previewredhat-user-workloads/openshift-local-extAffected
Red Hat Build of Podman Desktop - Tech Previewredhat-user-workloads/rhel-extWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2456179Vite: Vite: Information disclosure via WebSocket connection bypasses access control

EPSS

Процентиль: 85%
0.02907
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default "..."). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

CVSS3: 7.5
debian
4 месяца назад

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to bef ...

github
4 месяца назад

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

EPSS

Процентиль: 85%
0.02907
Низкий

7.5 High

CVSS3