{
  "@id": "urn:uuid:f7184f2b-f388-4014-ae90-d1f4ff6436e6",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T13:54:29.811509+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.3",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58751 does not affect version 6.4.3 of vite. not_affected \u2014 The target repository (Vite 6.4.3 at SHA a21f80eaf) is NOT AFFECTED by CVE-2025-58751. The vulnerability pattern (sirv library's improper directory boundary check using `startsWith()` without ensuring a trailing separator) was fixed by upstream Vite commit 63e2a5d23 authored by green@sapphi.red. The fix ensures the public directory path ends with a separator before comparison, preventing false ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-58751"
      },
      "impact_statement": "not_affected \u2014 The target repository (Vite 6.4.3 at SHA a21f80eaf) is NOT AFFECTED by CVE-2025-58751. The vulnerability pattern (sirv library's improper directory boundary check using `startsWith()` without ensuring a trailing separator) was fixed by upstream Vite commit 63e2a5d23 authored by green@sapphi.red. The fix ensures the public directory path ends with a separator before comparison, preventing false ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.3",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58752 does not affect version 6.4.3 of vite. not_affected \u2014 CVE-2025-58752 is not present in the target Vite 6.4.3 repository. The vulnerability was fixed by upstream Vite in version 6.3.6 via commit 0ab19ea9f. The fix adds filesystem access validation to the indexHtmlMiddleware, preventing unauthorized access to HTML files outside allowed directories. Since the target version 6.4.3 is newer than 6.3.6, it inherits this upstream fix.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-58752"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-58752 is not present in the target Vite 6.4.3 repository. The vulnerability was fixed by upstream Vite in version 6.3.6 via commit 0ab19ea9f. The fix adds filesystem access validation to the indexHtmlMiddleware, preventing unauthorized access to HTML files outside allowed directories. Since the target version 6.4.3 is newer than 6.3.6, it inherits this upstream fix."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.3",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62522 does not affect version 6.4.3 of vite. not_affected \u2014 The target repository (Vite v6.4.3, SHA a21f80eaf) is NOT vulnerable to CVE-2025-62522. The upstream vendor fix from commit 1114b5d7e (released in Vite v6.4.1) is already present in the target codebase. This fix strips trailing slashes from file paths before checking against the server.fs.deny list, preventing attackers from bypassing the deny-list by appending trailing slashes or backslashes t...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62522"
      },
      "impact_statement": "not_affected \u2014 The target repository (Vite v6.4.3, SHA a21f80eaf) is NOT vulnerable to CVE-2025-62522. The upstream vendor fix from commit 1114b5d7e (released in Vite v6.4.1) is already present in the target codebase. This fix strips trailing slashes from file paths before checking against the server.fs.deny list, preventing attackers from bypassing the deny-list by appending trailing slashes or backslashes t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.3",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 6.4.3 of vite. CVE-2026-39363 is NOT present in Vite 6.4.3. The vulnerability (fetchModule accessible via WebSocket without server.fs access control) was fixed by upstream Vite maintainers in commit fe28e47e9 (\"fix: apply server.fs check to env transport #22159\"), released in v6.4.3 before TuxCare adoption. The fix disables fetchModule for client environments exposed via WebSocket by setting disableFetchModule: true, throwing an error before any file access occurs. All attribution rungs (A1-A4) failed - this is an upstream vendor fix, not a TuxCare backport.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "CVE-2026-39363 is NOT present in Vite 6.4.3. The vulnerability (fetchModule accessible via WebSocket without server.fs access control) was fixed by upstream Vite maintainers in commit fe28e47e9 (\"fix: apply server.fs check to env transport #22159\"), released in v6.4.3 before TuxCare adoption. The fix disables fetchModule for client environments exposed via WebSocket by setting disableFetchModule: true, throwing an error before any file access occurs. All attribution rungs (A1-A4) failed - this is an upstream vendor fix, not a TuxCare backport."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.3",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.3"
          }
        }
      ],
      "timestamp": "2026-09-30T13:54:29.811509+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 affects version 6.4.3 of vite, and is fixed in 6.4.3-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "action_statement": "Vulnerability CVE-2026-39364 affects version 6.4.3 of vite, and is fixed in 6.4.3-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.3",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.3"
          }
        }
      ],
      "timestamp": "2026-09-30T13:54:29.811509+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 affects version 6.4.3 of vite, and is fixed in 6.4.3-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-39365"
      },
      "action_statement": "Vulnerability CVE-2026-39365 affects version 6.4.3 of vite, and is fixed in 6.4.3-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@6.4.3",
          "identifiers": {
            "purl": "pkg:npm/vite@6.4.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 does not affect version 6.4.3 of vite. The target Vite v6.4.3 is NOT affected by CVE-2026-53571. The vulnerability (Windows path bypass via NTFS ADS and 8.3 short names) has been fixed by upstream commit 96b0c10162e9c55485d922db2cfc6b8227cbc176, which was included in the original v6.4.3 release. The fix adds checks in `isFileLoadingAllowed()` to reject paths containing `~` (8.3 short names) and `:` after drive letters (NTFS ADS), preventing attackers from accessing files that should be blocked by `server.fs.deny`.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53571"
      },
      "impact_statement": "The target Vite v6.4.3 is NOT affected by CVE-2026-53571. The vulnerability (Windows path bypass via NTFS ADS and 8.3 short names) has been fixed by upstream commit 96b0c10162e9c55485d922db2cfc6b8227cbc176, which was included in the original v6.4.3 release. The fix adds checks in `isFileLoadingAllowed()` to reject paths containing `~` (8.3 short names) and `:` after drive letters (NTFS ADS), preventing attackers from accessing files that should be blocked by `server.fs.deny`."
    }
  ]
}
