CVE-2026-39364: CWE-180: Incorrect Behavior Order: Validate Before Canonicalize in vitejs vite
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-39364) in Vite occurs due to incorrect behavior order in validating before canonicalizing file paths on the Vite development server. Specifically, files that should be blocked by the server.fs.deny configuration, such as environment variable files (.env) and certificate files (*.crt), can be accessed by appending query parameters like ?raw, ?import&raw, or ?import&url&inline to the request URL. This bypasses intended security restrictions, resulting in unauthorized disclosure of sensitive files. The flaw is present in Vite versions from 7.1.0 up to but not including 7.3.2, and from versions before 8.0.5. The vulnerability is tracked under CWE-180 (Incorrect Behavior Order), CWE-284 (Improper Access Control), and CWE-472 (External Control of Assumed-Immutable Web Parameter). Red Hat advisories confirm the issue and provide no direct mitigation other than upgrading to fixed versions. The vulnerability has a high CVSS score of 8.2, reflecting its network attack vector, low complexity, no privileges or user interaction required, and high confidentiality impact.
Potential Impact
Successful exploitation allows remote attackers to bypass file access restrictions on the Vite development server and retrieve sensitive files that should be blocked, including environment configuration files and certificate files. This unauthorized disclosure of sensitive information could facilitate further compromise of the affected system or environment. The vulnerability does not impact integrity or availability but poses a high confidentiality risk.
Mitigation Recommendations
The vulnerability is fixed in Vite versions 7.3.2 and 8.0.5. Users should upgrade to these or later versions to remediate the issue. According to the Red Hat advisory, no alternative mitigation is currently available that meets their criteria for ease of use, applicability, and stability. Therefore, upgrading to a fixed version is the recommended remediation.
CVE-2026-39364: CWE-180: Incorrect Behavior Order: Validate Before Canonicalize in vitejs vite
Description
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.
CVSS v4.0
Score 8.2high
Affected software
vitejs
vite
vitejs
vite-plus
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-39364) in Vite occurs due to incorrect behavior order in validating before canonicalizing file paths on the Vite development server. Specifically, files that should be blocked by the server.fs.deny configuration, such as environment variable files (.env) and certificate files (*.crt), can be accessed by appending query parameters like ?raw, ?import&raw, or ?import&url&inline to the request URL. This bypasses intended security restrictions, resulting in unauthorized disclosure of sensitive files. The flaw is present in Vite versions from 7.1.0 up to but not including 7.3.2, and from versions before 8.0.5. The vulnerability is tracked under CWE-180 (Incorrect Behavior Order), CWE-284 (Improper Access Control), and CWE-472 (External Control of Assumed-Immutable Web Parameter). Red Hat advisories confirm the issue and provide no direct mitigation other than upgrading to fixed versions. The vulnerability has a high CVSS score of 8.2, reflecting its network attack vector, low complexity, no privileges or user interaction required, and high confidentiality impact.
Potential Impact
Successful exploitation allows remote attackers to bypass file access restrictions on the Vite development server and retrieve sensitive files that should be blocked, including environment configuration files and certificate files. This unauthorized disclosure of sensitive information could facilitate further compromise of the affected system or environment. The vulnerability does not impact integrity or availability but poses a high confidentiality risk.
Mitigation Recommendations
The vulnerability is fixed in Vite versions 7.3.2 and 8.0.5. Users should upgrade to these or later versions to remediate the issue. According to the Red Hat advisory, no alternative mitigation is currently available that meets their criteria for ease of use, applicability, and stability. Therefore, upgrading to a fixed version is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-06T21:29:17.349Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-39364","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24866","vendor":"Red Hat"}]
Threat ID: 69d55f07aaed68159a562944
Added to database: 04/07/2026, 19:46:15 UTC
Last enriched: 08/17/2026, 13:17:52 UTC
Last updated: 09/14/2026, 22:01:33 UTC
Views: 282
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.