Vulnerability intelligence
CVE-2026-39364
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.
CVSS Score
8.2
High
EPSS — Exploit Probability
2.0%
Riskier than 80% of all CVEs · checked 2026-09-15
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Sep 15, 2026 · latest Sep 15, 2026
Coverage timeline
-
Attackers Exploit Vite Flaw to Steal Cloud Credentials from Serverssecurityonline.info · Sep 15, 2026