{
  "@id": "urn:uuid:ec62a1d1-14da-4941-a385-87bd60beb1ea",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T09:13:13.236749+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T09:13:13.236749+00:00",
      "status_notes": "Vulnerability CVE-2026-39363 does not affect version 7.3.3-tuxcare.1 of vite. The target repository (Vite 7.3.3 at SHA 56498fb61) is not affected by CVE-2026-39363. The vulnerability, which allowed arbitrary file access via WebSocket `vite:invoke` events to the `fetchModule` method bypassing `server.fs` restrictions, was fixed by upstream Vite in commit 19db0f29c. This fix is already present in the target version. The defense disables `fetchModule` for client dev environments (which expose WebSocket to the network), preventing the attack path described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39363"
      },
      "impact_statement": "The target repository (Vite 7.3.3 at SHA 56498fb61) is not affected by CVE-2026-39363. The vulnerability, which allowed arbitrary file access via WebSocket `vite:invoke` events to the `fetchModule` method bypassing `server.fs` restrictions, was fixed by upstream Vite in commit 19db0f29c. This fix is already present in the target version. The defense disables `fetchModule` for client dev environments (which expose WebSocket to the network), preventing the attack path described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T09:13:13.236749+00:00",
      "status_notes": "Vulnerability CVE-2026-39364 does not affect version 7.3.3-tuxcare.1 of vite. The target repository (Vite v7.3.3) is not affected by CVE-2026-39364. The vulnerability allowed bypassing server.fs.deny restrictions by appending query parameters (?raw, ?import&raw, etc.) to file requests. The upstream vendor fix (commit f8103cc94) was included in Vite v7.3.2 and is present in the target v7.3.3. The fix adds access control validation on both the cleaned URL (without query parameters) and the full URL, preventing the bypass. This is an upstream vendor fix, not a TuxCare backport.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39364"
      },
      "impact_statement": "The target repository (Vite v7.3.3) is not affected by CVE-2026-39364. The vulnerability allowed bypassing server.fs.deny restrictions by appending query parameters (?raw, ?import&raw, etc.) to file requests. The upstream vendor fix (commit f8103cc94) was included in Vite v7.3.2 and is present in the target v7.3.3. The fix adds access control validation on both the cleaned URL (without query parameters) and the full URL, preventing the bypass. This is an upstream vendor fix, not a TuxCare backport."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T09:13:13.236749+00:00",
      "status_notes": "Vulnerability CVE-2026-39365 affects version 7.3.3-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-39365"
      },
      "action_statement": "Vulnerability CVE-2026-39365 affects version 7.3.3-tuxcare.1 of vite."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T09:13:13.236749+00:00",
      "status_notes": "Vulnerability CVE-2026-53571 is fixed in version 7.3.3-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53571"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/vite@7.3.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/vite@7.3.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T09:13:13.236749+00:00",
      "status_notes": "Vulnerability CVE-2026-53632 is fixed in version 7.3.3-tuxcare.1 of vite.",
      "vulnerability": {
        "name": "CVE-2026-53632"
      }
    }
  ]
}
