{
  "@id": "urn:uuid:d2e20017-4c6f-4a62-b75d-f98dad3a5aa3",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23331 does not affect version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-23331. The fix (adding 'nocase: true' to picomatch options) has been applied and is present in the current codebase.",
      "vulnerability": {
        "name": "CVE-2024-23331"
      },
      "impact_statement": "Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-23331. The fix (adding 'nocase: true' to picomatch options) has been applied and is present in the current codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-31207 does not affect version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy. not_affected - CVE-2024-31207 (server.fs.deny bypass for patterns containing directories) was fixed upstream in vite 5.2.6 / 5.1.7 / 5.0.13 / 4.5.3 / 3.2.10 / 2.9.18. This project version is vite 4.5.5, i.e. above the 4.5.3 fix in the same 4.5.x line, so the fix is already present and no patch is needed. The previous patch_application_error state came from the automation's pre-validation reporting 'Patches already applied'.",
      "vulnerability": {
        "name": "CVE-2024-31207"
      },
      "impact_statement": "not_affected - CVE-2024-31207 (server.fs.deny bypass for patterns containing directories) was fixed upstream in vite 5.2.6 / 5.1.7 / 5.0.13 / 4.5.3 / 3.2.10 / 2.9.18. This project version is vite 4.5.5, i.e. above the 4.5.3 fix in the same 4.5.x line, so the fix is already present and no patch is needed. The previous patch_application_error state came from the automation's pre-validation reporting 'Patches already applied'."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45811 does not affect version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-45811. The fix is present in a semantically equivalent form, using `checkServingAccess` with `deniedServingAccessForTransform` instead of the vendor's `ensureServingAccess`, but providing identical protection against the ?import&raw bypass vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-45811"
      },
      "impact_statement": "Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-45811. The fix is present in a semantically equivalent form, using `checkServingAccess` with `deniedServingAccessForTransform` instead of the vendor's `ensureServingAccess`, but providing identical protection against the ?import&raw bypass vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52011 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2024-52011"
      },
      "action_statement": "Vulnerability CVE-2024-52011 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.9."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-24010 is fixed in version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-24010"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-30208 is fixed in version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-30208"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31125 is fixed in version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-31125"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31486 is fixed in version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-31486"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32395 is fixed in version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-32395"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46565 is fixed in version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-46565"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58751 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2025-58751"
      },
      "action_statement": "Vulnerability CVE-2025-58751 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.9."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58752 is fixed in version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy.",
      "vulnerability": {
        "name": "CVE-2025-58752"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62522 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.7.",
      "vulnerability": {
        "name": "CVE-2025-62522"
      },
      "action_statement": "Vulnerability CVE-2025-62522 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.7."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39363 does not affect Vite 4.5.5. The vulnerability requires fetchModule method and vite:invoke WebSocket event, which were introduced in later versions (5.x/6.x). [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "Version 4.5.5 is not vulnerable. Summary: CVE-2026-39363 does not affect Vite 4.5.5. The vulnerability requires fetchModule method and vite:invoke WebSocket event, which were introduced in later versions (5.x/6.x). [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 does not affect version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy. vite 4.5.5 is outside the affected version range for CVE-2026-39364 per the GitHub Security Advisory and NIST/NVD.",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "impact_statement": "vite 4.5.5 is outside the affected version range for CVE-2026-39364 per the GitHub Security Advisory and NIST/NVD."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 does not affect version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39365 path traversal vulnerability was present in the original Vite v4.5.5 but has been patched in version 4.5.5-tuxcare.7. The fix (commit 91f0a4f50, backported on 2026-04-20) adds validation to ensure .map file requests for optimized dependencies cannot traverse outside the optimized deps directory via '../' segments in the URL. The target repository currently includes this security patch. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39365"
      },
      "impact_statement": "Version 4.5.5 is not vulnerable. Summary: CVE-2026-39365 path traversal vulnerability was present in the original Vite v4.5.5 but has been patched in version 4.5.5-tuxcare.7. The fix (commit 91f0a4f50, backported on 2026-04-20) adds validation to ensure .map file requests for optimized dependencies cannot traverse outside the optimized deps directory via '../' segments in the URL. The target repository currently includes this security patch. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-53571"
      },
      "action_statement": "Vulnerability CVE-2026-53571 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53632 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.8.",
      "vulnerability": {
        "name": "CVE-2026-53632"
      },
      "action_statement": "Vulnerability CVE-2026-53632 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.8."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4w7w-66w2-5vf9 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.7.",
      "vulnerability": {
        "name": "GHSA-4w7w-66w2-5vf9"
      },
      "action_statement": "Vulnerability GHSA-4w7w-66w2-5vf9 affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.7."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40vitejs/plugin-legacy@4.5.5-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v2wj-q39q-566r affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.7.",
      "vulnerability": {
        "name": "GHSA-v2wj-q39q-566r"
      },
      "action_statement": "Vulnerability GHSA-v2wj-q39q-566r affects version 4.5.5-tuxcare.6 of @vitejs/plugin-legacy, and is fixed in 4.5.5-tuxcare.7."
    }
  ]
}
