Vite Flaw Exploited to Steal AWS, Azure Credentials — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- F5 Labs disclosed the automated mass-scanning campaign, observed in August 2026, which targets internet-exposed Vite development servers to siphon cloud and system secrets.
- CVE-2026-39364 (CVSS 8.2) — a flaw Vite itself disclosed in April 2026 — lets unauthenticated attackers bypass server.fs.deny by appending query parameters like ?raw, ?import&raw, or ?import&url&inline to /@fs/ requests, returning normally blocked files (e.g., .env, *.crt) with HTTP 200.
- Exploitation requires three conditions: the dev server must be explicitly exposed via --host or server.host, the sensitive file must sit in an allowed directory, and it must be matched by a deny pattern — conditions F5 said are triggered by misconfigured Docker port mappings and default-overridden binds.
- Attackers extracted AWS credentials and configs, Azure profiles, infrastructure state files (terraform.tfstate, serverless.yml), and system memory artifacts (/etc/passwd, /proc/self/environ, /proc/self/cwd/.env), with the .env probing demonstrating knowledge of the live deployment stack.
- The reconnaissance traffic impersonates Googlebot, ClaudeBot, GPTBot, PerplexityBot, OAI-SearchBot, and Amazonbot, and spoofs X-Forwarded-For/X-Real-IP headers (e.g., 34.94.237.62, 104.28.219.193) to slip past IP allow-lists and corrupt log analysis.
- Activity originated primarily from the U.S., Belgium, the Netherlands, Singapore, and Taiwan, with attackers leveraging Google Cloud Platform IP ranges (34.x and 35.x) to disguise the source of the scans.
Why it matters: Developers who exposed Vite dev servers — often a quick `npm run dev --host` shortcut or a misconfigured Docker mapping — handed attackers plaintext AWS/Azure admin keys, database passwords, and Terraform state, which is effectively a master key to their cloud tenancy. With scanning volumes originating across five countries and routed through Google Cloud IP space, organizations should audit any publicly reachable dev servers immediately and confirm Vite is patched against CVE-2026-39364.
Ask SkimNews




