Skip to content

fix: update Vite 7.3.2 (CVE-2026-39363)#431

Merged
jesposito merged 1 commit intomainfrom
fix/vite-cve-2026-39363
Apr 7, 2026
Merged

fix: update Vite 7.3.2 (CVE-2026-39363)#431
jesposito merged 1 commit intomainfrom
fix/vite-cve-2026-39363

Conversation

@jesposito
Copy link
Copy Markdown
Owner

Patch bump Vite 7.3.1 -> 7.3.2 to fix CVE-2026-39363 (arbitrary file read via dev server WebSocket).

Dev-server-only vulnerability - no production impact. Semver patch release.

Fixes arbitrary file read via Vite dev server WebSocket vulnerability.
@jesposito jesposito merged commit 02ac970 into main Apr 7, 2026
10 checks passed
@jesposito jesposito deleted the fix/vite-cve-2026-39363 branch April 20, 2026 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant