Vite是Vite开源的一种新型的前端构建工具。 Vite 7.1.0至7.3.2之前版本和8.0.5之前版本存在访问控制错误漏洞,该漏洞源于服务器文件拒绝列表可被绕过,可能导致检索应被阻止的文件。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Vite is a modern frontend build tool. In Vite prior to versions 6.4.3, 6.3.4, and 5.4.23, a directory traversal vulnerability affects the Vite development server. When the Vite dev server is launched with the --host or server.host option, an unauthenticated attacker can craft a request with a path containing dot segments (e.g., /.vite/../<filename>) to bypass static file restrictions and access arbitrary files on the filesystem under the project root. The vulnerability allows access to files normally denied by Vite’s "server.fs.deny" setting, including sensitive files like .env, configuration files, or credentials in the project root. This issue has been fixed in versions 6.4.3, 6.3.4, and 5.4.23. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-39364.yaml | POC详情 |
| CVE-2026-39363 | 8.2 HIGH | Vite 访问控制错误漏洞 |
| CVE-2026-39365 | Vite 路径遍历漏洞 |
暂无评论