{
  "@id": "urn:uuid:f6a4d7e4-b203-4d0b-913f-d973293e3d99",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 7.3.2-tuxcare.1 of vite. The target (Vite v7.3.2) is NOT affected by CVE-2026-39363. The vulnerability\u2014whereby `fetchModule` exposed via WebSocket bypassed `server.fs` access control\u2014was fixed in upstream commit 19db0f29c (\"fix: backport #22159, apply server.fs check to env transport\") which was included in Vite v7.3.2 before release. The fix disables `fetchModule` for client (network-exposed) environments by setting `disableFetchModule: true` in config.ts and throwing an error in environment.ts when invoked. This blocks the attack path from WebSocket `vite:invoke` messages to arbitrary file content. The fix was authored by upstream Vite maintainer green@sapphi.red, not by TuxCare, so the verdict is not_affected (vendor-fix case) rather than already_fixed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "The target (Vite v7.3.2) is NOT affected by CVE-2026-39363. The vulnerability\u2014whereby `fetchModule` exposed via WebSocket bypassed `server.fs` access control\u2014was fixed in upstream commit 19db0f29c (\"fix: backport #22159, apply server.fs check to env transport\") which was included in Vite v7.3.2 before release. The fix disables `fetchModule` for client (network-exposed) environments by setting `disableFetchModule: true` in config.ts and throwing an error in environment.ts when invoked. This blocks the attack path from WebSocket `vite:invoke` messages to arbitrary file content. The fix was authored by upstream Vite maintainer green@sapphi.red, not by TuxCare, so the verdict is not_affected (vendor-fix case) rather than already_fixed."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 does not affect version 7.3.2-tuxcare.1 of vite. vite 7.3.2 is outside the affected version range for CVE-2026-39364 per the GitHub Security Advisory and NIST/NVD.",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "impact_statement": "vite 7.3.2 is outside the affected version range for CVE-2026-39364 per the GitHub Security Advisory and NIST/NVD."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 does not affect version 7.3.2-tuxcare.1 of vite. not_affected \u2014 CVE-2026-39365 is NOT present in the target repository. The vulnerability describes a path traversal attack in Vite v7.3.1's optimized dependencies sourcemap handler, allowing attackers to read arbitrary .map files outside the project root by injecting ../ segments in URLs. The target is at version v7.3.2, which includes the upstream fix (commit 09d8c903b) that validates resolved paths using is...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39365"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-39365 is NOT present in the target repository. The vulnerability describes a path traversal attack in Vite v7.3.1's optimized dependencies sourcemap handler, allowing attackers to read arbitrary .map files outside the project root by injecting ../ segments in URLs. The target is at version v7.3.2, which includes the upstream fix (commit 09d8c903b) that validates resolved paths using is..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 is fixed in version 7.3.2-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53571"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53632 is fixed in version 7.3.2-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53632"
      }
    }
  ]
}
