CVE-2026-41211: Voidzero Vite+

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make Vite+ delete, replace, and populate directories outside the intended cache location. Version 0.1.17 contains a patch.

Affected products

  • Voidzero Vite+: before 0.1.17 (fixed in 0.1.17)

Published 2026-04-23. Last modified 2026-06-17.