4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether vite-plus is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-53632
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
HIGH 7.5
CVE-2026-53571
vite: `server.fs.deny` bypass on Windows alternate paths
CRITICAL 9.8
CVE-2026-53633
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
CRITICAL 10.0
CVE-2026-41211
Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes