Skip to content
Threat Feed

Vendor

Vite

4 briefs RSS
high threat

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials

A mass-scanning campaign is actively exploiting CVE-2026-39364 in internet-exposed Vite development servers to bypass security restrictions and exfiltrate sensitive cloud credentials and configuration files.

exploited Vite
1r 3t 1c 2i
high advisory

Threat Actors Impersonate AI Crawlers to Exfiltrate Sensitive Credentials

Threat actors are using forged User-Agent strings to masquerade as AI crawlers from OpenAI, Anthropic, and other firms to scan for and exfiltrate environment files and cloud credentials from misconfigured web servers.

PoC Vite credential-theft web-scraping scanning reconnaissance
1r 2t 1c updated
high advisory

Vite Dev Server `server.fs.deny` Bypass on Windows (CVE-2026-53571)

A high-severity vulnerability (CVE-2026-53571) in the Vite development server on Windows allows threat actors to bypass `server.fs.deny` restrictions, leading to information disclosure of sensitive files like `.env` or `tls.pem` via crafted HTTP requests utilizing NTFS Alternate Data Streams or 8.3 short names, impacting applications that expose the dev server to the network.

PoC Vite +4 information-disclosure bypass web-vulnerability windows development-server
2r 1t 1c 3i updated
high advisory

Vite Arbitrary File Read Vulnerability via WebSocket

Vite versions 6.0.0 to 8.0.4 are vulnerable to arbitrary file read, allowing attackers to bypass access controls and retrieve the contents of arbitrary files on the server via the WebSocket path when the dev server is exposed to the network.

Vite file-read vulnerability websocket
2r 1t