{
  "@id": "urn:uuid:d4c2f44d-540c-4109-9652-13b9e419283f",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-03T10:14:00.118059+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-24010 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-24010"
      },
      "action_statement": "Vulnerability CVE-2025-24010 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-30208 is fixed in version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-30208"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-31125 is fixed in version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-31125"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-31486 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-31486"
      },
      "action_statement": "Vulnerability CVE-2025-31486 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-32395 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-32395"
      },
      "action_statement": "Vulnerability CVE-2025-32395 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-46565 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-46565"
      },
      "action_statement": "Vulnerability CVE-2025-46565 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-58751 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-58751"
      },
      "action_statement": "Vulnerability CVE-2025-58751 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-58752 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-58752"
      },
      "action_statement": "Vulnerability CVE-2025-58752 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2025-62522 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2025-62522"
      },
      "action_statement": "Vulnerability CVE-2025-62522 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T07:12:50.005810+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 5.4.10-tuxcare.1 of vite. CVE-2026-39363 affects Vite 6.x+ with the Environment API, not version 5.4.10. The vulnerability describes arbitrary file access via WebSocket's `vite:invoke` event calling `fetchModule` without server.fs checks. Version 5.4.10 lacks the vulnerable code path: (1) no `environment.ts`/`DevEnvironment` class exists, (2) no `vite:invoke` WebSocket handler is registered, (3) while `ssrFetchModule` exists and bypasses fs checks internally, it is NOT exposed to WebSocket clients. The Environment API that introduced this WebSocket-based module loading was added in Vite 6.0, over 1750 commits after the target version. Only the `vite:invalidate` WebSocket handler exists in 5.4.10. The vulnerability chain (external WebSocket client \u2192 vite:invoke \u2192 fetchModule \u2192 unprotected file read) is not reachable in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "CVE-2026-39363 affects Vite 6.x+ with the Environment API, not version 5.4.10. The vulnerability describes arbitrary file access via WebSocket's `vite:invoke` event calling `fetchModule` without server.fs checks. Version 5.4.10 lacks the vulnerable code path: (1) no `environment.ts`/`DevEnvironment` class exists, (2) no `vite:invoke` WebSocket handler is registered, (3) while `ssrFetchModule` exists and bypasses fs checks internally, it is NOT exposed to WebSocket clients. The Environment API that introduced this WebSocket-based module loading was added in Vite 6.0, over 1750 commits after the target version. Only the `vite:invalidate` WebSocket handler exists in 5.4.10. The vulnerability chain (external WebSocket client \u2192 vite:invoke \u2192 fetchModule \u2192 unprotected file read) is not reachable in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T10:14:00.118059+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 does not affect version 5.4.10-tuxcare.1 of vite. Vite 5.4.10 is not affected by CVE-2026-39364. The vulnerability affects versions 7.1.0 to before 7.3.2 and 8.0.0 to before 8.0.5. Version 5.4.10 has defensive code that strips query parameters before checking server.fs.deny rules via the fsPathFromUrl\u2192cleanUrl chain and the CVE-2024-45811 fix (commit 6820bb3b9). The vulnerable pattern was introduced in version 7.1.0 during architectural refactoring when functions like isServerAccessDeniedForTransform and checkLoadingAccess were added, and does not exist in the 5.4.x codebase.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "impact_statement": "Vite 5.4.10 is not affected by CVE-2026-39364. The vulnerability affects versions 7.1.0 to before 7.3.2 and 8.0.0 to before 8.0.5. Version 5.4.10 has defensive code that strips query parameters before checking server.fs.deny rules via the fsPathFromUrl\u2192cleanUrl chain and the CVE-2024-45811 fix (commit 6820bb3b9). The vulnerable pattern was introduced in version 7.1.0 during architectural refactoring when functions like isServerAccessDeniedForTransform and checkLoadingAccess were added, and does not exist in the 5.4.x codebase."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-39365"
      },
      "action_statement": "Vulnerability CVE-2026-39365 affects version 5.4.10-tuxcare.1 of vite."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@5.4.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@5.4.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T21:40:55.761767+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 affects version 5.4.10-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53571"
      },
      "action_statement": "Vulnerability CVE-2026-53571 affects version 5.4.10-tuxcare.1 of vite."
    }
  ]
}
