CVE-2026-41211
CRITICAL`vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`
Title source: cnaDescription
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/voidzero-dev/vite-plus/security/advisories/GHSA-33r3-4whc-44c2
Scores
CVSS v3
10.0
EPSS
0.0031
EPSS Percentile
22.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (3)
npm/vite-plus
0 - 0.1.17npm
voidzero/vite\+
< 0.1.17
voidzero-dev/vite-plus
< 0.1.17
Published
Apr 23, 2026
Tracked Since
Apr 23, 2026