CVE-2026-41211
CVE-2026-41211 is a critical-severity vulnerability in Voidzero Vite+ with a CVSS 3.x base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Critical (CVSS 3.x base score 10.0)
- CVSS v4: 8.4
- EPSS exploit prediction: 0% (35th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-25163
- Weakness: CWE-22
- Affected product: Voidzero Vite+
- Published:
- Last modified:
Description
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.
Frequently asked questions
- What is CVE-2026-41211?
- Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.
- How severe is CVE-2026-41211?
- CVE-2026-41211 has a CVSS 3.x base score of 10.0, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability high.
- Is CVE-2026-41211 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (35th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-41211?
- CVE-2026-41211 affects Voidzero Vite+. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-41211?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-41211 have an EU (EUVD) identifier?
- Yes. CVE-2026-41211 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-25163.
- When was CVE-2026-41211 published?
- CVE-2026-41211 was published on 2026-04-23 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:voidzero:vite\+:*:*:*:*:*:node.js:*:*
More vulnerabilities in Voidzero Vite+
- CVE-2026-53571 — High (CVSS 7.5): Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are…
- CVE-2026-39364 — High (CVSS 7.5): Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server,…
- CVE-2026-39363 — High (CVSS 7.5): Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to…
- CVE-2026-39365 — Medium (CVSS 5.3): Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s…
All CVEs affecting Voidzero Vite+ →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-55393 — Critical (CVSS 10.0): Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9…
- CVE-2026-97163 — Critical (CVSS 10.0): Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1,…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9,…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.