{
  "@id": "urn:uuid:7c739e34-5f6d-4a6a-9c96-e5245afea028",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58751 does not affect version 6.4.2-tuxcare.2 of vite. not_affected \u2014 The target repository (Vite 6.4.2 at SHA b3673ed76) is NOT affected by CVE-2025-58751. The vulnerability pattern is not present because the upstream Vite vendor already applied the fix in commits e11d24008 (sirv 3.0.2 upgrade) and c22c43de6 (shouldServe integration), both authored by sapphi-red. These commits prevent the path traversal attack by ensuring directory paths end with a separator bef...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-58751"
      },
      "impact_statement": "not_affected \u2014 The target repository (Vite 6.4.2 at SHA b3673ed76) is NOT affected by CVE-2025-58751. The vulnerability pattern is not present because the upstream Vite vendor already applied the fix in commits e11d24008 (sirv 3.0.2 upgrade) and c22c43de6 (shouldServe integration), both authored by sapphi-red. These commits prevent the path traversal attack by ensuring directory paths end with a separator bef..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58752 does not affect version 6.4.2-tuxcare.2 of vite. not_affected \u2014 CVE-2025-58752 affects Vite's HTML file serving and sourcemap handling, allowing path traversal to read arbitrary files outside configured root directories. The target repository (Vite 6.4.2) contains fixes for both vulnerabilities, applied by upstream vendor commits 0ab19ea9f (HTML files) and ca4da5d1f (sourcemaps). Both commits are authored by green@sapphi.red, an upstream Vite maintainer, no...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-58752"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-58752 affects Vite's HTML file serving and sourcemap handling, allowing path traversal to read arbitrary files outside configured root directories. The target repository (Vite 6.4.2) contains fixes for both vulnerabilities, applied by upstream vendor commits 0ab19ea9f (HTML files) and ca4da5d1f (sourcemaps). Both commits are authored by green@sapphi.red, an upstream Vite maintainer, no..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62522 does not affect version 6.4.2-tuxcare.2 of vite. not_affected \u2014 CVE-2025-62522 has been fixed in the target version 6.4.2. The upstream vendor fix from vitejs/vite v6.4.1 (commit 1114b5d7e) is present, which strips trailing slashes from file paths before checking against server.fs.deny patterns. The vulnerable code pattern where URLs ending with \\ or / could bypass deny-list checks no longer exists.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62522"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-62522 has been fixed in the target version 6.4.2. The upstream vendor fix from vitejs/vite v6.4.1 (commit 1114b5d7e) is present, which strips trailing slashes from file paths before checking against server.fs.deny patterns. The vulnerable code pattern where URLs ending with \\ or / could bypass deny-list checks no longer exists."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 6.4.2-tuxcare.2 of vite. The target is not affected by CVE-2026-39363. The vulnerability allowed attackers to read arbitrary server files via WebSocket by invoking fetchModule without server.fs access control checks. An upstream vendor fix (commit fe28e47e9) has already been applied in the target repository, which completely disables fetchModule for the client environment exposed via WebSocket, throwing an error when invoked. The vulnerable pattern (unprotected fetchModule accessible via network WebSocket) is no longer present in the target code.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "The target is not affected by CVE-2026-39363. The vulnerability allowed attackers to read arbitrary server files via WebSocket by invoking fetchModule without server.fs access control checks. An upstream vendor fix (commit fe28e47e9) has already been applied in the target repository, which completely disables fetchModule for the client environment exposed via WebSocket, throwing an error when invoked. The vulnerable pattern (unprotected fetchModule accessible via network WebSocket) is no longer present in the target code."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 does not affect version 6.4.2-tuxcare.2 of vite. Version 6.4.2 is not affected by CVE-2026-39364. The vulnerability was introduced in v7.1.0 when the protective `deniedServingAccessForTransform()` function was removed during an architectural refactoring. Version 6.4.2 uses a different code architecture that includes this defensive function, which checks file access against deny patterns using the cleaned URL (query parameters stripped) before the potentially vulnerable `isServerAccessDeniedForTransform()` function is reached. This provides runtime protection that prevents the bypass described in the CVE.",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "impact_statement": "Version 6.4.2 is not affected by CVE-2026-39364. The vulnerability was introduced in v7.1.0 when the protective `deniedServingAccessForTransform()` function was removed during an architectural refactoring. Version 6.4.2 uses a different code architecture that includes this defensive function, which checks file access against deny patterns using the cleaned URL (query parameters stripped) before the potentially vulnerable `isServerAccessDeniedForTransform()` function is reached. This provides runtime protection that prevents the bypass described in the CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 affects version 6.4.2-tuxcare.2 of vite.",
      "vulnerability": {
        "name": "CVE-2026-39365"
      },
      "action_statement": "Vulnerability CVE-2026-39365 affects version 6.4.2-tuxcare.2 of vite."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 is fixed in version 6.4.2-tuxcare.2 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53571"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.2-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.2-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53632 is fixed in version 6.4.2-tuxcare.2 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53632"
      }
    }
  ]
}
