CRITICAL10.0npm
GHSA-33r3-4whc-44c2· CVE-2026-41211Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
Modified: 5/6/2026
package
pkg:npm/vite-plus
Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
Modified: 5/6/2026
vite: `server.fs.deny` bypass on Windows alternate paths
Modified: 9/10/2026
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Modified: 8/13/2026
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Modified: 9/10/2026