{"id":"GHSA-v2wj-q39q-566r","summary":"Vite: `server.fs.deny` bypassed with queries","details":"### Summary\n\nThe contents of files that are specified by [`server.fs.deny`](https://vite.dev/config/server-options#server-fs-deny) can be returned to the browser.\n\n### Impact\n\nOnly apps that match the following conditions are affected:\n\n- explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))\n- the sensitive file exists in the allowed directories specified by [`server.fs.allow`](https://vite.dev/config/server-options#server-fs-allow)\n- the sensitive file is denied with a pattern that matches a file by [`server.fs.deny`](https://vite.dev/config/server-options#server-fs-deny)\n\n### Details\n\nOn the Vite dev server, files that should be blocked by `server.fs.deny` (e.g., `.env`, `*.crt`) can be retrieved with HTTP 200 responses when query parameters such as `?raw`, `?import&raw`, or `?import&url&inline` are appended.\n\n### PoC\n\n1. Start the dev server: `pnpm exec vite root --host 127.0.0.1 --port 5175 --strictPort`\n2. Confirm that `server.fs.deny` is enforced (expect 403): `curl -i http://127.0.0.1:5175/src/.env | head -n 20`\n   \u003cimg width=\"3944\" height=\"1092\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ecb9f2e0-e08f-4ac7-b194-e0f988c4cd4f\" /\u003e\n3. Confirm that the same files can be retrieved with query parameters (expect 200):\n   \u003cimg width=\"2014\" height=\"373\" alt=\"image\" src=\"https://github.com/user-attachments/assets/76bc2a6a-44f4-4161-ae47-eab5ae0c04a8\" /\u003e","aliases":["CVE-2026-39364"],"modified":"2026-09-10T03:50:44.780128889Z","published":"2026-04-06T18:03:32Z","database_specific":{"cwe_ids":["CWE-180","CWE-284"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-06T18:03:32Z","nvd_published_at":"2026-04-07T20:16:30Z"},"references":[{"type":"WEB","url":"https://github.com/vitejs/vite/security/advisories/GHSA-v2wj-q39q-566r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39364"},{"type":"WEB","url":"https://github.com/vitejs/vite/pull/22160"},{"type":"WEB","url":"https://github.com/vitejs/vite/commit/a9a3df299378d9cbc5f069e3536a369f8188c8ff"},{"type":"PACKAGE","url":"https://github.com/vitejs/vite"},{"type":"WEB","url":"https://github.com/vitejs/vite/releases/tag/v7.3.2"},{"type":"WEB","url":"https://github.com/vitejs/vite/releases/tag/v8.0.5"}],"affected":[{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.0.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.0.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-v2wj-q39q-566r/GHSA-v2wj-q39q-566r.json"}},{"package":{"name":"vite","ecosystem":"npm","purl":"pkg:npm/vite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.1.0"},{"fixed":"7.3.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 7.3.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-v2wj-q39q-566r/GHSA-v2wj-q39q-566r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}