{
  "@id": "urn:uuid:1109d96e-c2d8-4030-8f41-178b4e94e19b",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23331 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2024-23331"
      },
      "action_statement": "Vulnerability CVE-2024-23331 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-31207 does not affect version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy. Version 3.2.11 is not vulnerable. Summary: The target repository (Vite v3.2.11) is NOT vulnerable to CVE-2024-31207. The vulnerability was introduced in v3.2.0 (commit df560b02d, 2022-09-22) and fixed in v3.2.9 (commit 89c7c645f, 2024-03-24). The current version includes the complete fix that properly handles server.fs.deny patterns with directories. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-31207"
      },
      "impact_statement": "Version 3.2.11 is not vulnerable. Summary: The target repository (Vite v3.2.11) is NOT vulnerable to CVE-2024-31207. The vulnerability was introduced in v3.2.0 (commit df560b02d, 2022-09-22) and fixed in v3.2.9 (commit 89c7c645f, 2024-03-24). The current version includes the complete fix that properly handles server.fs.deny patterns with directories. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45811 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2024-45811"
      },
      "action_statement": "Vulnerability CVE-2024-45811 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52011 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy, and is fixed in 3.2.11-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2024-52011"
      },
      "action_statement": "Vulnerability CVE-2024-52011 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy, and is fixed in 3.2.11-tuxcare.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-24010 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-24010"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-30208 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-30208"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31125 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-31125"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31486 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-31486"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32395 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-32395"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46565 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-46565"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58751 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-58751"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58752 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-58752"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62522 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-62522"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy. Version 3.2.11 is not vulnerable. Summary: Target repository (Vite 3.2.11-tuxcare.1) predates the introduction of the vulnerable feature. The fetchModule method exposed via WebSocket (vite:invoke event) does not exist in this version. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "Version 3.2.11 is not vulnerable. Summary: Target repository (Vite 3.2.11-tuxcare.1) predates the introduction of the vulnerable feature. The fetchModule method exposed via WebSocket (vite:invoke event) does not exist in this version. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 does not affect version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy. CVE-2026-39364 affects Vite versions 7.1.0 through 7.3.1 and 8.0.0 through 8.0.4. Version 3.2.11 predates the vulnerable architecture introduced in v7.1.0. The v3.2.11 codebase already strips query parameters via fsPathFromUrl()->cleanUrl() before checking server.fs.deny patterns, preventing the bypass described in the CVE. The attack chain (module IDs with query parameters bypassing deny checks) requires the v7+ architecture and does not apply to the older v3.2.11 implementation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "impact_statement": "CVE-2026-39364 affects Vite versions 7.1.0 through 7.3.1 and 8.0.0 through 8.0.4. Version 3.2.11 predates the vulnerable architecture introduced in v7.1.0. The v3.2.11 codebase already strips query parameters via fsPathFromUrl()->cleanUrl() before checking server.fs.deny patterns, preventing the bypass described in the CVE. The attack chain (module IDs with query parameters bypassing deny checks) requires the v7+ architecture and does not apply to the older v3.2.11 implementation."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 is fixed in version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2026-39365"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy, and is fixed in 3.2.11-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-53571"
      },
      "action_statement": "Vulnerability CVE-2026-53571 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy, and is fixed in 3.2.11-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@3.2.11-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53632 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy, and is fixed in 3.2.11-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-53632"
      },
      "action_statement": "Vulnerability CVE-2026-53632 affects version 3.2.11-tuxcare.2 of @vitejs/plugin-legacy, and is fixed in 3.2.11-tuxcare.3."
    }
  ]
}
