Threat Intelligence

Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials

The Hacker News · 15 Sept 2026
Key Takeaway Never expose Vite or other development servers to the internet; keep them bound to localhost, patch to the latest Vite version, and rotate any credentials stored in .env files on servers that may have been reachable externally.

Security researchers at F5 Labs have detailed an automated scanning campaign targeting internet-exposed Vite development servers, aimed at stealing cloud credentials and sensitive configuration data from AWS, Azure and infrastructure state files. The campaign, observed in August 2026, exploits CVE-2026-39364, a high-severity flaw in Vite that lets an unauthenticated attacker bypass security restrictions by manipulating query parameters in HTTP requests.

Normally, Vite blocks access to sensitive files such as .env and certificate files through a setting called server.fs.deny. However, by appending specific query parameters to requests, attackers can trick the server into returning these files in plaintext. This becomes a serious risk when a development server has been exposed to the local network or the internet, for example by using the --host flag, changing server.host settings, or misconfiguring Docker port mappings, since Vite binds to localhost by default and is not meant to be publicly reachable.

F5 Labs observed attackers using this technique to probe for API secrets, database passwords and cloud administrative credentials, including requests designed to identify the underlying deployment stack without needing to guess file paths. This kind of reconnaissance can give attackers a direct route into cloud environments if credentials are successfully harvested.

Vite cloud security vulnerability credential theft development servers

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.