<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:30:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-263815</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263815</link>
      <description>EUVD-2026-263815</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263815</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68155</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68155</link>
      <description>&lt;p&gt;@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.5.8 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.5.8 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68155</guid>
    </item>
    <item>
      <title>GHSA-g239-q96q-x4qm — @vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g239-q96q-x4qm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @vitejs/plugin-rsc&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows **unauthenticated arbitrary file read** during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter.&lt;/p&gt;
&lt;p&gt;**Severity:** High
**Attack Vector:** Network  
**Privileges Required:** None  
**Scope:** Development mode only (`vite dev`)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;### Who Is Affected?&lt;/p&gt;
&lt;p&gt;- **All developers** using `@vitejs/plugin-rsc` during development
- Projects running `vite dev` with the RSC plugin enabled&lt;/p&gt;
&lt;p&gt;### Attack Scenarios&lt;/p&gt;
&lt;p&gt;1. **Network-Exposed Dev Servers:**  
   When developers run `vite --host 0.0.0.0` (common for mobile testing), attackers on the same network can read files.&lt;/p&gt;
&lt;p&gt;2. ~**XSS-Based Attacks:**~
   ~If the application has an XSS vulnerability, malicious JavaScript can fetch sensitive files and exfiltrate them.~&lt;/p&gt;
&lt;p&gt;3. ~**Malicious Dependencies:** ~
   ~A compromised npm package could include code that reads files during development.~&lt;/p&gt;
&lt;p&gt;4. ~**DNS Rebinding:**~ (EDIT: This doesn&amp;#39;t apply since https://github.com/vitejs/vite/pull/20222)
   ~An attacker could use DNS rebinding to access the localhost dev server from a malicious website.~&lt;/p&gt;
&lt;p&gt;### What Can Be Leaked?&lt;/p&gt;
&lt;p&gt;- Environment files (`.env`, `.env.local`, `.env.production`)
- SSH keys (`~/.ssh/id_rsa`, `~/.ssh/id_ed25519`)
- Cloud credentials (`~/.aws/credentials`, `~/.config/gcloud/`)
- Database passwords and API keys
- Source code…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @vitejs/plugin-rsc&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows **unauthenticated arbitrary file read** during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter.&lt;/p&gt;
&lt;p&gt;**Severity:** High
**Attack Vector:** Network  
**Privileges Required:** None  
**Scope:** Development mode only (`vite dev`)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;### Who Is Affected?&lt;/p&gt;
&lt;p&gt;- **All developers** using `@vitejs/plugin-rsc` during development
- Projects running `vite dev` with the RSC plugin enabled&lt;/p&gt;
&lt;p&gt;### Attack Scenarios&lt;/p&gt;
&lt;p&gt;1. **Network-Exposed Dev Servers:**  
   When developers run `vite --host 0.0.0.0` (common for mobile testing), attackers on the same network can read files.&lt;/p&gt;
&lt;p&gt;2. ~**XSS-Based Attacks:**~
   ~If the application has an XSS vulnerability, malicious JavaScript can fetch sensitive files and exfiltrate them.~&lt;/p&gt;
&lt;p&gt;3. ~**Malicious Dependencies:** ~
   ~A compromised npm package could include code that reads files during development.~&lt;/p&gt;
&lt;p&gt;4. ~**DNS Rebinding:**~ (EDIT: This doesn&amp;#39;t apply since https://github.com/vitejs/vite/pull/20222)
   ~An attacker could use DNS rebinding to access the localhost dev server from a malicious website.~&lt;/p&gt;
&lt;p&gt;### What Can Be Leaked?&lt;/p&gt;
&lt;p&gt;- Environment files (`.env`, `.env.local`, `.env.production`)
- SSH keys (`~/.ssh/id_rsa`, `~/.ssh/id_ed25519`)
- Cloud credentials (`~/.aws/credentials`, `~/.config/gcloud/`)
- Database passwords and API keys
- Source code…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g239-q96q-x4qm</guid>
    </item>
  </channel>
</rss>
