MIRAGE
Threat IntelligenceCVEs › CVE-2026-39365

CVE-2026-39365 — exposed on the internet

CVE-2026-39365: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vitejs vite

Internet exposure observed by OffSeq scans · last 30 days

8
Exposed hosts
6.3
CVSS
0.9%
EPSS

Found on 8 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2026-39365

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.

Vendor: vitejsCWE-22

OffSeq internet scanning found CVE-2026-39365 on 8 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

http grafana

Open the live CVE-2026-39365 view →

References