CVE-2026-39363

Aliases:GHSA-P9FF-H696-F583GHSA-p9ff-h696-f583CGA-339j-5hpp-qcg8CGA-4mxr-738r-737vCGA-pg55-w8qq-hvw6CGA-pr54-4mcw-x8wwCGA-2mqq-mph8-frx5CGA-3v8p-pjcm-6c6rCGA-44qr-7fvm-9m35CGA-4g4v-v24p-v9vwCGA-53rp-gmfv-4x72CGA-555m-mhr5-6c6fCGA-57ww-pmh5-9p8vCGA-6228-6wqx-wv7gCGA-8866-q5cg-8xh6CGA-88rv-6jmq-fpg2CGA-8g83-84pv-hpvfCGA-8gqc-47j2-fwgrCGA-8mc2-xxp5-mfmjCGA-9wf2-cw2r-jfh4CGA-9wwq-6vqf-rj63CGA-cmv6-w4c8-c6r5CGA-cqfg-658c-68j9CGA-f385-rm64-9jxmCGA-fcjc-ww3h-896hCGA-fvqx-8cc3-fv52CGA-g49c-8275-gm54CGA-gjf2-8xc7-636qCGA-gvrc-r3q8-wv79CGA-gwcm-566v-3983CGA-h3wg-f57w-f3j3CGA-h57q-3xf2-jr8qCGA-h9xq-4h33-xvvrCGA-j3h4-vcmp-q2vjCGA-mhmq-xjq7-rxhxCGA-mx6g-4frw-qrffCGA-p25g-7wcp-jfqmCGA-pr73-fwmh-rj5rCGA-q8cv-7jm7-hjvxCGA-qc8m-mmfx-5h4wCGA-qh84-95rv-fr82CGA-qj8m-3r97-xc64CGA-v43h-52q9-j2qpCGA-v6qw-32pr-6879CGA-v93j-xq44-8jjcCGA-v9w9-prxj-qc66CGA-vjr6-v8v9-7qjmCGA-vq8r-w56f-wg79CGA-w986-jqww-f9mmCGA-w9hr-rh78-c8c4CGA-wxmf-fqjv-h84vCGA-xq7x-4rfg-chjqCGA-xv9q-f452-2w6qCGA-xxwr-69c8-8gqqCGA-28xq-q34m-4v66CGA-98p7-94qm-v4cqCGA-pgqv-v5r8-rrpxCGA-xcm9-rxc4-4vcgCGA-2pv8-c5hp-7hwpCGA-3x75-qq3j-2qfvCGA-g82v-f37q-rfcrCGA-m35v-45jx-j82fCGA-mqw5-xmjx-gccpCGA-wr5w-ch93-mm72
Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 07 Apr 2026, 19:10
Last modified:25 Aug 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
43/100
CVSS Score
8.2 HIGH
v4.0 (cve.org)
EPSS Score
3.4% LOW
3% probability +0.49%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

07 Apr 2026, 19:10
Published
Vulnerability first disclosed
25 Aug 2026, 12:05
Last Modified
Vulnerability information updated

Description

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default "..."). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

CVSS Metrics

  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 3.40% Percentile: 88%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • CWE-306Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

  • CWE-1220Insufficient Granularity of Access Control

    The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Affected Systems

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    < 19.1.2-r2

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    < 19.1.1-r3

  • chainguardgitlab-rails-ce-fips-19.2

    < 19.2.1-r1

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.179.1-r3

  • chainguardlangfuse-fips-3-worker

    < 3.179.1-r2

  • chainguardvite

    < 8.0.11-r0

  • chainguardvitess-22

    < 22.0.4-r9

  • chainguardvitess-23

    < 23.0.3-r11

  • wolfilangfuse-3-compat

    < 3.225.7-r6

  • wolfilangfuse-3-worker

    < 3.179.1-r3

  • wolfivite

    < 8.0.11-r0

  • wolfivitess-23

    < 23.0.3-r11

  • Npmvite

    ≥ 8.0.0, < 8.0.5 | ≥ 7.0.0, < 7.3.2 | ≥ 6.0.0, < 6.4.2

  • vitejsvite

    ≥ 8.0.0, < 8.0.5 | ≥ 7.0.0, < 7.3.2 | ≥ 6.0.0, < 6.4.2 | ≥ 6.0.0, ≤ 6.4.1 | ≥ 7.0.0, ≤ 7.3.1 | ≥ 8.0.0, ≤ 8.0.4

  • vitejsvite-plus

    ≤ 0.1.15 | < 0.1.16

  • voidzerovite\+

    ≤ 0.1.15

References (16)