Voidzero

Vite+

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.59%
  • Veröffentlicht 22.06.2026 16:10:58
  • Zuletzt bearbeitet 24.06.2026 20:44:24

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files th...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 23.04.2026 00:56:15
  • Zuletzt bearbeitet 29.04.2026 15:49:45

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute pa...