CVE-2026-39363
Vulnerability Summary
Timeline
Description
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default "..."). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.
CVSS Metrics
- v4.0•HIGH•Score: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- v4.0•HIGH•Score: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 3.40%• Percentile: 88%
Techniques & Countermeasures
- CWE-200•Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-306•Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
- CWE-1220•Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Affected Systems
- chainguard•commercial-gitlab-rails-ee-19.1
all
- chainguard•commercial-gitlab-rails-ee-19.2
all
- chainguard•commercial-gitlab-rails-ee-19.3
all
- chainguard•commercial-gitlab-rails-ee-fips-19.1
all
- chainguard•commercial-gitlab-rails-ee-fips-19.3
all
- chainguard•gitlab-rails-ce-18.1
all
- chainguard•gitlab-rails-ce-18.10
all
- chainguard•gitlab-rails-ce-18.11
all
- chainguard•gitlab-rails-ce-18.5
all
- chainguard•gitlab-rails-ce-18.6
all
- chainguard•gitlab-rails-ce-18.7
all
- chainguard•gitlab-rails-ce-18.8
all
- chainguard•gitlab-rails-ce-18.9
all
- chainguard•gitlab-rails-ce-19.0
all
- chainguard•gitlab-rails-ce-19.1
< 19.1.2-r2
- chainguard•gitlab-rails-ce-fips-18.1
all
- chainguard•gitlab-rails-ce-fips-18.10
all
- chainguard•gitlab-rails-ce-fips-18.11
all
- chainguard•gitlab-rails-ce-fips-18.5
all
- chainguard•gitlab-rails-ce-fips-18.6
all
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
all
- chainguard•gitlab-rails-ce-fips-19.0
all
- chainguard•gitlab-rails-ce-fips-19.1
< 19.1.1-r3
- chainguard•gitlab-rails-ce-fips-19.2
< 19.2.1-r1
- chainguard•langfuse-3-compat
< 3.225.7-r6
- chainguard•langfuse-3-worker
< 3.179.1-r3
- chainguard•langfuse-fips-3-worker
< 3.179.1-r2
- chainguard•vite
< 8.0.11-r0
- chainguard•vitess-22
< 22.0.4-r9
- chainguard•vitess-23
< 23.0.3-r11
- wolfi•langfuse-3-compat
< 3.225.7-r6
- wolfi•langfuse-3-worker
< 3.179.1-r3
- wolfi•vite
< 8.0.11-r0
- wolfi•vitess-23
< 23.0.3-r11
- Npm•vite
≥ 8.0.0, < 8.0.5 | ≥ 7.0.0, < 7.3.2 | ≥ 6.0.0, < 6.4.2
- vitejs•vite
≥ 8.0.0, < 8.0.5 | ≥ 7.0.0, < 7.3.2 | ≥ 6.0.0, < 6.4.2 | ≥ 6.0.0, ≤ 6.4.1 | ≥ 7.0.0, ≤ 7.3.1 | ≥ 8.0.0, ≤ 8.0.4
- vitejs•vite-plus
≤ 0.1.15 | < 0.1.16
- voidzero•vite\+
≤ 0.1.15
References (16)
- https://github.com/vitejs/vite/security/advisories/GHSA-p9ff-h696-f583
- https://github.com/vitejs/vite/pull/22159
- https://github.com/vitejs/vite/commit/f02d9fde0b195afe3ea2944414186962fbbe41e0
- https://github.com/vitejs/vite
- https://github.com/vitejs/vite/releases/tag/v6.4.2
- https://github.com/vitejs/vite/releases/tag/v7.3.2
- https://github.com/vitejs/vite/releases/tag/v8.0.5
- https://nvd.nist.gov/vuln/detail/CVE-2026-39363
- https://access.redhat.com/security/cve/CVE-2026-39363
- https://bugzilla.redhat.com/show_bug.cgi?id=2456179
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39363.json
- https://access.redhat.com/errata/RHSA-2026:24761
- https://access.redhat.com/errata/RHSA-2026:24762
- https://access.redhat.com/errata/RHSA-2026:24866
- https://access.redhat.com/errata/RHSA-2026:59153
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39363.json