{"id":"CVE-2026-41211","aliases":["GHSA-33r3-4whc-44c2"],"url":"https://o3.security/vulnerability/CVE-2026-41211","summary":"`vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`","details":"Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.","published":"2026-04-23T00:56:15.568Z","modified":"2026-07-15T01:49:02.183321013Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"vite-plus","fixedVersion":"0.1.17"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41211.json"},{"type":"ADVISORY","url":"https://github.com/voidzero-dev/vite-plus/security/advisories/GHSA-33r3-4whc-44c2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41211"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.183321013Z"}}