216.73.216.197

CVE-2026-41211

· Published 23/04/2026 02:16 · Modified 24/04/2026 14:50

Labels: CVE-2026-41211 2026-04-23CVE-2026-41211CWE-22[email protected]

Essential information

Published
23/04/2026 02:16
Modified
24/04/2026 14:50
Author
Creator
CVSS
8.4 HIGH (v3) 8.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vite / vite cpe:2.3:a:vite:vite:*:*:*:*:*:*:*:*

References