<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 01:12:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292723</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292723</link>
      <description>EUVD-2026-292723</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292723</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41211</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41211</link>
      <description>&lt;p&gt;Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/&amp;lt;pm&amp;gt;/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/&amp;lt;pm&amp;gt;/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41211</guid>
    </item>
    <item>
      <title>GHSA-33r3-4whc-44c2 — Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-33r3-4whc-44c2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite-plus&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`downloadPackageManager()` in `vite-plus/binding` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments to escape the `VP_HOME/package_manager/&amp;lt;pm&amp;gt;/` cache root and cause Vite+ to delete, replace, and populate directories outside the intended cache location.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The public `vite-plus/binding` export `downloadPackageManager()` forwards `options.version` directly into the Rust package-manager download flow without validating that it is a normal semver version.&lt;/p&gt;
&lt;p&gt;That value is used as a path component when building the install location under `VP_HOME`. After the package is downloaded and extracted, Vite+:&lt;/p&gt;
&lt;p&gt;1. computes the final target directory from the raw `version` string,
2. removes any pre-existing directory at that target,
3. renames the extracted package into that location, and
4. writes executable shim files there.&lt;/p&gt;
&lt;p&gt;Because the CLI validates versions via `semver::Version::parse()` before calling this code, the protection that exists for normal `vp create`, `vp migrate`, and `vp env` flows does not apply to direct callers of the binding. A programmatic caller of `vite-plus/binding` can pass traversal strings such as `../../../escaped` and break out of `VP_HOME`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
import fs from &amp;#34;node:fs&amp;#34;;
import http from &amp;#34;node:http&amp;#34;;
import os from &amp;#34;node:os&amp;#34;;
import path from &amp;#34;node:path&amp;#34;;
import { downloadPackageManager } from &amp;#34;vite-plus/binding&amp;#34;;&lt;/p&gt;
&lt;p&gt;const tgz = Buffer.from(
  &amp;#34;H4sIAH/B1GkC/+3…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite-plus&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`downloadPackageManager()` in `vite-plus/binding` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments to escape the `VP_HOME/package_manager/&amp;lt;pm&amp;gt;/` cache root and cause Vite+ to delete, replace, and populate directories outside the intended cache location.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The public `vite-plus/binding` export `downloadPackageManager()` forwards `options.version` directly into the Rust package-manager download flow without validating that it is a normal semver version.&lt;/p&gt;
&lt;p&gt;That value is used as a path component when building the install location under `VP_HOME`. After the package is downloaded and extracted, Vite+:&lt;/p&gt;
&lt;p&gt;1. computes the final target directory from the raw `version` string,
2. removes any pre-existing directory at that target,
3. renames the extracted package into that location, and
4. writes executable shim files there.&lt;/p&gt;
&lt;p&gt;Because the CLI validates versions via `semver::Version::parse()` before calling this code, the protection that exists for normal `vp create`, `vp migrate`, and `vp env` flows does not apply to direct callers of the binding. A programmatic caller of `vite-plus/binding` can pass traversal strings such as `../../../escaped` and break out of `VP_HOME`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
import fs from &amp;#34;node:fs&amp;#34;;
import http from &amp;#34;node:http&amp;#34;;
import os from &amp;#34;node:os&amp;#34;;
import path from &amp;#34;node:path&amp;#34;;
import { downloadPackageManager } from &amp;#34;vite-plus/binding&amp;#34;;&lt;/p&gt;
&lt;p&gt;const tgz = Buffer.from(
  &amp;#34;H4sIAH/B1GkC/+3…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-33r3-4whc-44c2</guid>
    </item>
  </channel>
</rss>
