High-Severity Vulnerability in Vite Development Servers Actively Exploited (CVE-2026-39364)
The Cyber Security Agency of Singapore (CSA) has issued an alert regarding the active exploitation of a high-severity vulnerability (CVE-2026-39364) in Vite development servers. Attackers are leveraging this flaw to bypass security configurations and retrieve restricted system and configuration files over HTTP. The vulnerability, with a CVSS v3.1 score of 7.5, affects Vite versions 7.1.0 to 7.3.1 and 8.0.0 to 8.0.4, as well as Vite-plus versions 0.1.15 and earlier, urging immediate patching.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai