¡¾Îó²îͨ¸æ¡¿Vite Dev Server WebSocket í§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2026-39363)
Ðû²¼Ê±¼ä 2026-04-09Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Vite Dev Server WebSocket í§ÒâÎļþ¶ÁÈ¡Îó²î | ||
CVE ID | CVE-2026-39363 | ||
Îó²îÀàÐÍ | í§ÒâÎļþ¶ÁÈ¡ | ·¢Ã÷ʱ¼ä | 2026-4-9 |
Îó²îÆÀ·Ö | 8.2 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
ViteÊÇÒ»¸öÏÖ´ú»¯µÄǰ¶Ë¹¹½¨¹¤¾ß£¬£¬£¬£¬£¬£¬Ö¼ÔÚÌṩ¸ü¿ìµÄ¿ª·¢ÌåÑé¡£¡£¡£¡£¡£Ëüͨ¹ý»ùÓÚÔÉúESÄ£¿£¿£¿£¿éµÄ¿ª·¢Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬ÔÚ¿ª·¢Àú³ÌÖÐʵÏÖ¼«ËÙÈȸüУ¨HMR£©¡£¡£¡£¡£¡£ViteÔÚ¹¹½¨Ê±Ê¹ÓÃÁ˸߶ÈÓÅ»¯µÄ´ò°ü¹¤¾ß£¬£¬£¬£¬£¬£¬Èçesbuild£¬£¬£¬£¬£¬£¬¼«´óÌá¸ßÁ˹¹½¨ËÙÂÊ¡£¡£¡£¡£¡£ËüÖ§³Ö¶àÖÖǰ¶Ë¿ò¼Ü£¨ÈçReact¡¢Vue£©²¢¿ÉÒÔͨ¹ý²å¼þÀ©Õ¹¹¦Ð§¡£¡£¡£¡£¡£ViteµÄÄ¿µÄÊǼò»¯Ç°¶Ë¿ª·¢ÊÂÇéÁ÷£¬£¬£¬£¬£¬£¬²¢ÌáÉý¿ª·¢Ð§ÂÊ¡£¡£¡£¡£¡£
2026Äê4ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬918²©ÌìÌÃÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Vite Dev Server WebSocketí§ÒâÎļþ¶ÁÈ¡Îó²î¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚVite dev server WebSocket̻¶µÄfetchModuleÒªÁìδ׼ȷִÐÐserver.fs»á¼û¿ØÖƼì²é£¬£¬£¬£¬£¬£¬µ¼ÖÂHTTP·¾¶ÏÂÔ±¾ÊÜÏÞµÄÎļþϵͳ»á¼ûÏÞÖÆ¿É±»Èƹý¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÖª×ãÌØ¶¨Ìõ¼þÏ£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½á¹¹vite:invoke WebSocketÊÂÎñ£¬£¬£¬£¬£¬£¬²¢Á¬Ïµfile://...Óë?raw»ò?inline²ÎÊý£¬£¬£¬£¬£¬£¬¶ÁÈ¡¿ª·¢»ú¡¢CIÇéÐλòÈÝÆ÷ÖеÄí§ÒâÎļþÄÚÈÝ¡£¡£¡£¡£¡£¸ÃÎÊÌâ¿ÉÄܵ¼ÖÂÔ´Âë¡¢ÃÜÔ¿¡¢ÉèÖÃÎļþ¼°ÇéÐαäÁ¿Ð¹Â¶£¬£¬£¬£¬£¬£¬½ø¶øÒý·¢½øÒ»²½ÈëÇÖ¡¢ºáÏòÒÆ¶¯»ò¹©Ó¦Á´Î£º¦¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
8.0.0 <= vite <= 8.0.4
7.0.0 <= vite <= 7.3.1
6.0.0 <= vite <= 6.4.1
vite-plus <= 0.1.15
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£
vite >= 8.0.5
vite >= 7.3.2
vite >= 6.4.2
vite-plus >= 0.1.16
ÏÂÔØÁ´½Ó£ºhttps://github.com/vitejs/vite/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£
? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2026-39363/


¾©¹«Íø°²±¸11010802024551ºÅ