Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
- ID
- 24646
- Status
- summarized
- Published
- 15 Sep 2026, 7:12 PM
- Fetched
- 15 Sep 2026, 9:26 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 15 Sep 2026, 9:28 PM
- Tags
- Audience
- developersvibe_coders
What happened
F5 Labs disclosed a mass-scanning campaign observed in August 2026 exploiting CVE-2026-39364 (CVSS 8.2) in Vite, where attackers append query parameters like ?raw, ?import&raw, or ?import&url&inline to /@fs/ requests to bypass server.fs.deny and read sensitive files (.env, certs, AWS/Azure credentials) from dev servers exposed via --host or server.host config. Default Vite binds to localhost, so only misconfigured deployments are affected.
Why it matters
If you run Vite dev servers with --host or server.host set (including misconfigured Docker port mappings), check immediately whether they were internet-exposed and rotate any AWS, Azure, database, or API credentials that may have been in .env or config files. The exploit is trivial (a crafted GET request) and actively scanned for, so exposure likely means compromise.
Discussion angle
How many teams in the community have accidentally exposed a Vite dev server via --host or Docker port mapping, and what's the practical checklist for detecting past exposure and rotating credentials without downtime?