Summary
A mass-scanning campaign is actively exploiting CVE-2026-39364, a high-severity file access control bypass in Vite development servers, to steal AWS credentials, Azure access tokens, environment variables, and infrastructure-as-code secrets from internet-exposed instances. F5 Labs detected the campaign through honeypot sensors, recording more than 800 session-grouped attacks and approximately 32,000 raw events over a single month in August 2026 — a sharp increase from only 1,732 Vite-related file-read events observed over the prior three months. The vulnerability affects Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5. Vite normally binds to localhost, but developers frequently expose it via --host flags or misconfigured Docker port mappings, creating the attack surface this campaign exploits.
Timeline
| Date | Event |
|---|---|
| April 7, 2026 | CVE-2026-39364 disclosed; affects Vite 7.1.0-7.3.2 and 8.x before 8.0.5 |
| May-July 2026 | 1,732 Vite file-read events observed — low baseline activity |
| August 2026 | F5 honeypot sensors detect sharp escalation: 800+ attacks and 32,000 raw events in one month |
| Sep 15, 2026 | F5 Labs publishes full campaign analysis including C2 IPs to blocklist and exploit wordlists |
What Happened
CVE-2026-39364 is a file access control bypass in Vite’s development server. Vite’s server.fs.deny configuration is intended to block access to files outside the project root, including sensitive files like .env and certificates. The vulnerability allows an unauthenticated attacker to bypass this restriction by appending specific query parameters to an HTTP GET request: when parameters such as ?raw, ?import&raw, or ?import&url&inline are appended to a file path request, the server fails to enforce deny-list filtering and returns the requested file in plaintext with an HTTP 200 response.
Attackers use carefully assembled wordlists to systematically request high-value credential files including .env, .env.local, .env.production, and .env.staging files; AWS credential and configuration files; AWS SSO caches and rootkey.csv; Azure accessTokens.json and credential files; Terraform state and variable files; Serverless Framework configuration; /proc/self/environ, /proc/1/environ; and /etc/passwd. The campaign also chained older Vite access-control vulnerabilities (CVE-2025-30208, CVE-2025-31125, CVE-2024-45811) against servers that may have partially patched newer issues, and used traversal and double-encoded sequences to evade WAF and reverse proxy normalization.
Attack traffic originated primarily from IP addresses in the United States, Belgium, and the Netherlands using Google Cloud IP ranges. F5 identified three primary source IPs that should be blocklisted: 34.14.15[.]105, 34.16.200[.]129, and 34.11.196[.]206. Organizations should update to Vite 7.3.3 or 8.0.5 or later, block external access to port 5173, restrict access to /@fs/ requests, and rotate all secrets accessible from any exposed server.
Domain Intelligence
vitejs.dev — 61.14
vitejs.dev scores in the low-trust range at 61.14. Vite is the vendor of the affected development server software. Patches for CVE-2026-39364 are available. The score reflects vitejs.dev’s domain trust posture independently of the severity of the vulnerability in its product.
The Trust Observatory · thetrustobservatory.com · September 15, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026