Voidzero
Security Risk Profile
48
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 6, 2026 to present
4
Total CVEs
3
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
7.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
48/100
medium
Severity Distribution
Critical
0High
3Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Path Traversal
2
2
Infoleak
2
Most Affected Products
1. npm/vite8
2. vitejs Vite Node.js8
3. Voidzero Vite\+ Node.js4
4. npm/vite-plus1
Recent Vulnerabilities
See more →CVE-2026-41211
CVSS 8.4high
`vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`
4/23/2026🔧 No Patch
CVE-2026-39365
CVSS 6.3medium
Vite has a Path Traversal in Optimized Deps `.map` Handling
4/6/2026
CVE-2026-39364
CVSS 8.2high
Vite has a `server.fs.deny` bypass with queries
4/6/2026
CVE-2026-39363
CVSS 8.2high
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
4/6/2026
Monitor Voidzero in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.