The record
Written from the 1 report below. Nothing here is unsourced.
- A mass-scanning campaign is exploiting a high-severity flaw in Vite development servers to steal sensitive data.
- The flaw, tracked as CVE-2026-39364, lets an unauthenticated attacker bypass security restrictions by adding query parameters to file requests.
- Attackers used the exploit to extract cloud credentials, environment configurations, AWS and Azure settings, and infrastructure state files from exposed servers.
- The requests used fake User-Agent headers impersonating bots like Googlebot and ClaudeBot, plus forged IP headers to evade access controls.
- Stolen cloud credentials and database passwords could give attackers unauthorized access to organizations' infrastructure.
What to watch next
- Whether Vite users apply fixes or stop exposing dev servers with --host or server.host settings.
- Further F5 Labs findings on the scale and targets of the credential-harvesting campaign.
- Potential abuse of additional bypass query parameters or new spoofed bot User-Agent headers.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Vite
1 quote · 1 outlet
“On the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended”
In the article
…high-severity security flaw in Vite that could permit an unauthenticated attacker to bypass security restrictions via query parameter manipulation and leak sensitive data, including files specified by server.fs.deny. " On the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended ," Vite said in an advisory for the flaw in April 2026. Successful exploitation, however, requires three conditions to be met for an app to be deemed affected - - Explicitly exposes the Vite dev server to the network…
Coverage1
All filed from India
Named United States · Belgium · Netherlands · Singapore · Taiwan · Amazon Web Services · Microsoft Azure · Vite · F5 Labs · Google Cloud Platform
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
