Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-41211

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 22.6%
CVSS Severity
CVSS v3 Score 10.0
Products affected by CVE-2026-41211
  • Voidzero » Vite+ » Version: 0.1.0
    cpe:2.3:a:voidzero:vite+:0.1.0
  • Voidzero » Vite+ » Version: 0.1.1
    cpe:2.3:a:voidzero:vite+:0.1.1
  • Voidzero » Vite+ » Version: 0.1.10
    cpe:2.3:a:voidzero:vite+:0.1.10
  • Voidzero » Vite+ » Version: 0.1.11
    cpe:2.3:a:voidzero:vite+:0.1.11
  • Voidzero » Vite+ » Version: 0.1.12
    cpe:2.3:a:voidzero:vite+:0.1.12
  • Voidzero » Vite+ » Version: 0.1.13
    cpe:2.3:a:voidzero:vite+:0.1.13
  • Voidzero » Vite+ » Version: 0.1.14
    cpe:2.3:a:voidzero:vite+:0.1.14
  • Voidzero » Vite+ » Version: 0.1.15
    cpe:2.3:a:voidzero:vite+:0.1.15
  • Voidzero » Vite+ » Version: 0.1.16
    cpe:2.3:a:voidzero:vite+:0.1.16
  • Voidzero » Vite+ » Version: 0.1.2
    cpe:2.3:a:voidzero:vite+:0.1.2
  • Voidzero » Vite+ » Version: 0.1.3
    cpe:2.3:a:voidzero:vite+:0.1.3
  • Voidzero » Vite+ » Version: 0.1.4
    cpe:2.3:a:voidzero:vite+:0.1.4
  • Voidzero » Vite+ » Version: 0.1.5
    cpe:2.3:a:voidzero:vite+:0.1.5
  • Voidzero » Vite+ » Version: 0.1.6
    cpe:2.3:a:voidzero:vite+:0.1.6
  • Voidzero » Vite+ » Version: 0.1.7
    cpe:2.3:a:voidzero:vite+:0.1.7
  • Voidzero » Vite+ » Version: 0.1.8
    cpe:2.3:a:voidzero:vite+:0.1.8
  • Voidzero » Vite+ » Version: 0.1.9
    cpe:2.3:a:voidzero:vite+:0.1.9


Contact Us

Shodan ® - All rights reserved