{
  "@id": "urn:uuid:b64d892a-5717-4656-888a-c46a20e02a39",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-26T21:34:00.119934+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23331 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2024-23331"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-31207 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2024-31207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45811 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2024-45811"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45812 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2024-45812"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52011 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2024-52011"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-24010 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-24010"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-30208 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-30208"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31125 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-31125"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31486 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-31486"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32395 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-32395"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46565 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-46565"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58751 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-58751"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58752 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-58752"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-26T21:34:00.119934+00:00",
      "status_notes": "Vulnerability CVE-2025-62522 affects version 4.1.5-tuxcare.1 of vite, and is fixed in 4.1.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2025-62522"
      },
      "action_statement": "Vulnerability CVE-2025-62522 affects version 4.1.5-tuxcare.1 of vite, and is fixed in 4.1.5-tuxcare.2."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 4.1.5-tuxcare.1 of vite. Version 4.1.5 is NOT AFFECTED by CVE-2026-39363. The vulnerability concerns the `fetchModule` method exposed via WebSocket (`vite:invoke` event) bypassing `server.fs` access controls. This feature was introduced in Vite 6.0.0+ (commit 78dc4902f, PR #18362) and does not exist in version 4.1.5. Exhaustive analysis confirms no `fetchModule`, no `vite:invoke` handler, no `setInvokeHandler`, and no alternative WebSocket mechanism for reading arbitrary files. The only custom WebSocket handler in 4.1.5 is `vite:invalidate`, which only invalidates module graph entries and does not read files. This is Rule 5 Type A1: the INPUT (WebSocket message invoking fetchModule) is not received anywhere in the target codebase.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "Version 4.1.5 is NOT AFFECTED by CVE-2026-39363. The vulnerability concerns the `fetchModule` method exposed via WebSocket (`vite:invoke` event) bypassing `server.fs` access controls. This feature was introduced in Vite 6.0.0+ (commit 78dc4902f, PR #18362) and does not exist in version 4.1.5. Exhaustive analysis confirms no `fetchModule`, no `vite:invoke` handler, no `setInvokeHandler`, and no alternative WebSocket mechanism for reading arbitrary files. The only custom WebSocket handler in 4.1.5 is `vite:invalidate`, which only invalidates module graph entries and does not read files. This is Rule 5 Type A1: the INPUT (WebSocket message invoking fetchModule) is not received anywhere in the target codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 does not affect version 4.1.5-tuxcare.1 of vite. Version 4.1.5 is NOT affected by CVE-2026-39364. The vulnerability exists in versions 7.1.0 to before 7.3.2 and 8.0.5 due to a specific code pattern introduced during refactoring between version 4.x and 7.x. Version 4.1.5 uses a different implementation (checkServingAccess) that properly strips query parameters before checking server.fs.deny patterns, whereas vulnerable versions 7.x/8.x call checkLoadingAccess with uncleaned URLs, causing glob pattern matching to fail when query parameters like ?raw, ?import&raw, or ?import&url&inline are present.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "impact_statement": "Version 4.1.5 is NOT affected by CVE-2026-39364. The vulnerability exists in versions 7.1.0 to before 7.3.2 and 8.0.5 due to a specific code pattern introduced during refactoring between version 4.x and 7.x. Version 4.1.5 uses a different implementation (checkServingAccess) that properly strips query parameters before checking server.fs.deny patterns, whereas vulnerable versions 7.x/8.x call checkLoadingAccess with uncleaned URLs, causing glob pattern matching to fail when query parameters like ?raw, ?import&raw, or ?import&url&inline are present."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-39365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53571"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@4.1.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@4.1.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53632 is fixed in version 4.1.5-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53632"
      }
    }
  ]
}
