{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avitejsvite/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vitejs:vite:*:*:*:*:*:*:*:*","cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*","cpe:2.3:a:voidzero:vite\\+:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-39364"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vite (development server)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Vite"],"content_html":"\u003cp\u003eSince August 2026, threat actors have been conducting a mass-scanning campaign targeting Vite development servers exposed to the public internet or local networks. The campaign leverages CVE-2026-39364, a high-severity vulnerability (CVSS 8.2) that allows unauthenticated attackers to bypass 'server.fs.deny' restrictions. By appending specific query parameters (?raw, ?import\u0026amp;raw, or ?import\u0026amp;url\u0026amp;inline) to requests directed at the /@fs/ endpoint, attackers can trick the server into returning the contents of files that should be protected.\u003c/p\u003e\n\u003cp\u003eThe attackers specifically target sensitive files including AWS and Azure credentials, infrastructure state files (terraform.tfstate), serverless configurations, and system files like /etc/passwd or .env files. The campaign utilizes cloud provider IP ranges and spoofed User-Agent strings (mimicking popular crawlers like Googlebot and ClaudeBot) to evade detection and circumvent IP-based access control lists. This activity poses a critical risk to organizations that have misconfigured development environments, potentially leading to full cloud administrative compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs mass scanning to identify Vite development servers exposed via the --host flag or Docker misconfiguration.\u003c/li\u003e\n\u003cli\u003eAttacker sends HTTP GET requests to the /@fs/ endpoint of the target Vite server.\u003c/li\u003e\n\u003cli\u003eAttacker appends malicious query parameters (?raw, ?import\u0026amp;raw, or ?import\u0026amp;url\u0026amp;inline) to the URI to bypass the server.fs.deny logic.\u003c/li\u003e\n\u003cli\u003eAttacker includes forged 'X-Forwarded-For' and 'X-Real-IP' headers to bypass potential IP-based filtering or rate-limiting.\u003c/li\u003e\n\u003cli\u003eAttacker impersonates legitimate search engines or AI bots via 'User-Agent' headers to avoid automated security alerts.\u003c/li\u003e\n\u003cli\u003eThe Vite server processes the request, ignores the deny list due to the bypass, and returns the contents of the target sensitive file in the HTTP response body.\u003c/li\u003e\n\u003cli\u003eAttacker parses the plaintext response to extract API secrets, cloud credentials, and deployment environment variables for further access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to gain unauthorized access to cloud environments, internal configuration, and secrets. This has resulted in the theft of AWS credentials, Azure profiles, and infrastructure state files. The wide-scale nature of the campaign affects any organization using misconfigured Vite development servers, with observed activity originating from multiple global regions. Failure to mitigate this vulnerability risks complete lateral movement and compromise of production cloud infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize auditing all Vite development deployments to ensure they are not exposed to the internet.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict Vite development server access to 'localhost' (default) and verify that no '--host' or 'server.host' flags are used in public-facing or non-secured environments.\u003c/li\u003e\n\u003cli\u003eDeploy the webserver-based Sigma rule provided in this brief to detect the specific query parameter bypass attempts on the /@fs/ endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor proxy and web server logs for requests containing suspicious query parameters (?raw, ?import\u0026amp;raw) combined with spoofed crawlers in the User-Agent field.\u003c/li\u003e\n\u003cli\u003eRevoke and rotate any credentials or secrets found on servers where Vite was exposed to the network.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T12:29:18Z","date_published":"2026-09-15T12:29:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vite-scanning/","summary":"A mass-scanning campaign is actively exploiting CVE-2026-39364 in internet-exposed Vite development servers to bypass security restrictions and exfiltrate sensitive cloud credentials and configuration files.","title":"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials","url":"https://feed.craftedsignal.io/briefs/2026-09-vite-scanning/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vitejs:vite:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}