<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:44:46 +0000</lastBuildDate>
    <item>
      <title>BREW-vite-CVE-2026-39363 — Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket</title>
      <link>https://cve.radiocsirt.org/vuln/brew-vite-cve-2026-39363</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: vite&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;[`server.fs`](https://vite.dev/config/server-options#server-fs-strict) check was not enforced to the `fetchModule` method that is exposed in Vite dev server&amp;#39;s WebSocket.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- WebSocket is not disabled by `server.ws: false`&lt;/p&gt;
&lt;p&gt;Arbitrary files on the server (development machine, CI environment, container, etc.) can be exposed.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If it is possible to connect to the Vite dev server’s WebSocket **without an `Origin` header**, an attacker can invoke `fetchModule` via the custom WebSocket event `vite:invoke` and combine `file://...` with `?raw` (or `?inline`) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., `export default &amp;#34;...&amp;#34;`).&lt;/p&gt;
&lt;p&gt;The access control enforced in the HTTP request path (such as `server.fs.allow`) is not applied to this WebSocket-based execution path.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Start the dev server on the target 
   Example (used during validation with this repository):
   ```bash
   pnpm -C playground/alias exec vite --host 0.0.0.0 --port 5173
   ```&lt;/p&gt;
&lt;p&gt;2. Confirm that access is blocked via the HTTP path (example: arbitrary file)
   ```bash
   curl -i &amp;#39;http://localhost:5173/@fs/etc/passwd?raw&amp;#39;
   ```
   Result: `403 Restricted` (outside the allow list)
   &amp;lt;img width=&amp;#34;3898&amp;#34; height=&amp;#34;1014&amp;#34; a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: vite&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;[`server.fs`](https://vite.dev/config/server-options#server-fs-strict) check was not enforced to the `fetchModule` method that is exposed in Vite dev server&amp;#39;s WebSocket.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- WebSocket is not disabled by `server.ws: false`&lt;/p&gt;
&lt;p&gt;Arbitrary files on the server (development machine, CI environment, container, etc.) can be exposed.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If it is possible to connect to the Vite dev server’s WebSocket **without an `Origin` header**, an attacker can invoke `fetchModule` via the custom WebSocket event `vite:invoke` and combine `file://...` with `?raw` (or `?inline`) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., `export default &amp;#34;...&amp;#34;`).&lt;/p&gt;
&lt;p&gt;The access control enforced in the HTTP request path (such as `server.fs.allow`) is not applied to this WebSocket-based execution path.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Start the dev server on the target 
   Example (used during validation with this repository):
   ```bash
   pnpm -C playground/alias exec vite --host 0.0.0.0 --port 5173
   ```&lt;/p&gt;
&lt;p&gt;2. Confirm that access is blocked via the HTTP path (example: arbitrary file)
   ```bash
   curl -i &amp;#39;http://localhost:5173/@fs/etc/passwd?raw&amp;#39;
   ```
   Result: `403 Restricted` (outside the allow list)
   &amp;lt;img width=&amp;#34;3898&amp;#34; height=&amp;#34;1014&amp;#34; a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-vite-cve-2026-39363</guid>
    </item>
    <item>
      <title>EUVD-2026-358591</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358591</link>
      <description>EUVD-2026-358591</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358591</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39363</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39363</link>
      <description>&lt;p&gt;Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default &amp;#34;...&amp;#34;). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default &amp;#34;...&amp;#34;). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39363</guid>
    </item>
    <item>
      <title>GHSA-p9ff-h696-f583 — Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p9ff-h696-f583</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;[`server.fs`](https://vite.dev/config/server-options#server-fs-strict) check was not enforced to the `fetchModule` method that is exposed in Vite dev server&amp;#39;s WebSocket.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- WebSocket is not disabled by `server.ws: false`&lt;/p&gt;
&lt;p&gt;Arbitrary files on the server (development machine, CI environment, container, etc.) can be exposed.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If it is possible to connect to the Vite dev server’s WebSocket **without an `Origin` header**, an attacker can invoke `fetchModule` via the custom WebSocket event `vite:invoke` and combine `file://...` with `?raw` (or `?inline`) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., `export default &amp;#34;...&amp;#34;`).&lt;/p&gt;
&lt;p&gt;The access control enforced in the HTTP request path (such as `server.fs.allow`) is not applied to this WebSocket-based execution path.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Start the dev server on the target 
   Example (used during validation with this repository):
   ```bash
   pnpm -C playground/alias exec vite --host 0.0.0.0 --port 5173
   ```&lt;/p&gt;
&lt;p&gt;2. Confirm that access is blocked via the HTTP path (example: arbitrary file)
   ```bash
   curl -i &amp;#39;http://localhost:5173/@fs/etc/passwd?raw&amp;#39;
   ```
   Result: `403 Restricted` (outside the allow list)
   &amp;lt;img width=&amp;#34;3898&amp;#34; height=&amp;#34;1014&amp;#34; a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;[`server.fs`](https://vite.dev/config/server-options#server-fs-strict) check was not enforced to the `fetchModule` method that is exposed in Vite dev server&amp;#39;s WebSocket.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- WebSocket is not disabled by `server.ws: false`&lt;/p&gt;
&lt;p&gt;Arbitrary files on the server (development machine, CI environment, container, etc.) can be exposed.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If it is possible to connect to the Vite dev server’s WebSocket **without an `Origin` header**, an attacker can invoke `fetchModule` via the custom WebSocket event `vite:invoke` and combine `file://...` with `?raw` (or `?inline`) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., `export default &amp;#34;...&amp;#34;`).&lt;/p&gt;
&lt;p&gt;The access control enforced in the HTTP request path (such as `server.fs.allow`) is not applied to this WebSocket-based execution path.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Start the dev server on the target 
   Example (used during validation with this repository):
   ```bash
   pnpm -C playground/alias exec vite --host 0.0.0.0 --port 5173
   ```&lt;/p&gt;
&lt;p&gt;2. Confirm that access is blocked via the HTTP path (example: arbitrary file)
   ```bash
   curl -i &amp;#39;http://localhost:5173/@fs/etc/passwd?raw&amp;#39;
   ```
   Result: `403 Restricted` (outside the allow list)
   &amp;lt;img width=&amp;#34;3898&amp;#34; height=&amp;#34;1014&amp;#34; a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p9ff-h696-f583</guid>
    </item>
    <item>
      <title>RHSA-2026:24761 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:24761</link>
      <description>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions github.com/pallets/click: Pallets Click: Arbitrary command execution via command injection in click.edit() minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance Vite: Vite: Information disclosure via WebSocket connection bypasses access control cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions github.com/pallets/click: Pallets Click: Arbitrary command execution via command injection in click.edit() minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance Vite: Vite: Information disclosure via WebSocket connection bypasses access control cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:24761</guid>
    </item>
  </channel>
</rss>
