{"id":9495,"date":"2026-09-15T14:36:41","date_gmt":"2026-09-15T14:36:41","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9495"},"modified":"2026-09-15T14:36:41","modified_gmt":"2026-09-15T14:36:41","slug":"exposed-vite-servers-are-being-probed-for-aws-and-azure-credentials","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9495","title":{"rendered":"Exposed Vite servers are being probed for AWS and Azure credentials"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Attackers have opened a new front in their war on software developers: Vite servers, which they are probing for sensitive data including cloud credentials, infrastructure configuration and environment files.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.infoworld.com\/article\/2266193\/7-tools-transforming-javascript-development.html#:~:text=Vite%20was%20originally%20a%20build%20tool%20specifically%20for%20Vue%2C%20but%20it%20now%20supports%20general%20use\">Vite was created as a build tool for Vue<\/a>, a JavaScript framework for building user interfaces and web applications, but has now become a widely used development server and <a href=\"https:\/\/www.infoworld.com\/article\/2253289\/react-tutorial-get-started-with-the-reactjs-javascript-library.html#:~:text=Vite%20is%20now%20the%20standard%20choice%20for%20launching%20a%20new%20app%20from%20the%20React%20terminal%2C\">build tool <\/a>across the JavaScript ecosystem.<\/p>\n<p class=\"wp-block-paragraph\">F5 Labs reported that attackers sent more than 32,000 attempts to scan exposed <\/p>\n<p class=\"wp-block-paragraph\">Vite servers on its honeypot network, grouped into 807 attacks (or sessions), during August, a sharp increase from just 1,732 attempts over the previous three months.<\/p>\n<p class=\"wp-block-paragraph\">\u201cRather than target a single file, the scanning fleet systematically cycled through extensive wordlists of environment files, AWS keys, Azure tokens, and Infrastructure-as-Code state files,\u201d F5 threat researcher, <a href=\"https:\/\/www.linkedin.com\/in\/adam-metcalfe-pearce-7a05445b\/\" target=\"_blank\" rel=\"noopener\">Adam Metcalfe-Pearce<\/a>, wrote in a blog <a href=\"https:\/\/www.f5.com\/labs\/articles\/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364\" target=\"_blank\" rel=\"noopener\">post on F5\u2019s blog<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">F5 noted that Vite normally binds to localhost, but developers can expose it through the \u201c\u2013host\u201d option, server configuration, container port mappings or other deployment mistakes.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Scans targeted a file-access bypass<\/h2>\n<p class=\"wp-block-paragraph\">The activity targeted a recently disclosed vulnerability that allows unauthenticated attackers to bypass Vite\u2019s file-access restriction and retrieve files from the host system. Tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-39364\" target=\"_blank\" rel=\"noopener\">CVE-2026-39364<\/a>, the flaw allows attackers to bypass the \u201cserver.fs.deny\u201d deny-list protection used to prevent access to sensitive files.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen specific parameters such as ?raw, ?import&amp;raw, or ?import&amp;url&amp;inline are appended to a request, the server fails to enforce deny-list filtering and serves the target file with an HTTP 200 response,\u201d Metcalfe-Pearce wrote.<\/p>\n<p class=\"wp-block-paragraph\">Some requests also used double-encoded path traversal, which F5 said indicated an attempt to evade security controls such as reverse proxies and web application firewalls (<a href=\"https:\/\/www.csoonline.com\/article\/566615\/what-is-a-waf-12-top-web-application-firewalls-compared.html\">WAFs<\/a>).<\/p>\n<p class=\"wp-block-paragraph\">Assigned a severity rating of CVSS 8.2 ,the flaw affects Vite 7.1.0 through versions before 7.3.2 and <a href=\"https:\/\/www.infoworld.com\/article\/4154031\/local-first-browser-data-gets-real.html#:~:text=Vite%208.0%20arrives%20with%20unified%20Rolldown-based%20builds\">Vite 8 <\/a>versions before 8.0.5.<\/p>\n<p class=\"wp-block-paragraph\">F5 recommended updating Vite to a patched version, rotating potentially exposed secrets, ensuring development servers do not bind to external interfaces, and auditing Docker, Kubernetes and cloud configurations so development ports are not exposed to the public internet.<\/p>\n<p class=\"wp-block-paragraph\">The blog also shared the curated directory and credential wordlists the attackers used during these attacks.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Vite was part of a broader scanning pattern<\/h2>\n<p class=\"wp-block-paragraph\">F5 also observed attackers combining CVE-2026-39364 with older Vite file access vulnerabilities, including <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2025-30208\" target=\"_blank\" rel=\"noopener\">CVE-2025-30208<\/a>, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2025-31125\" target=\"_blank\" rel=\"noopener\">CVE-2025-31125 <\/a>and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-45811\" target=\"_blank\" rel=\"noopener\">CVE-2024-45811<\/a>. The same scanning infrastructure also probed for a Next.js middleware bypass, indicating that the activity is not confined to a single framework.<\/p>\n<p class=\"wp-block-paragraph\">In its blog post the company also noted that, apart from <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/01\/22\/cisa-adds-four-known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\">CVE-2025-31125<\/a>, none of these CVEs are yet listed in CISA\u2019s Known Exploited Vulnerabilities (KEV) catalog.<\/p>\n<p class=\"wp-block-paragraph\">While F5 saw a sharp increase in August in attacks on recently uncovered flaws in Vite, it didn\u2019t make the top three CVEs attacked on the company\u2019s honeypots, all of them much older. <a href=\"https:\/\/www.csoonline.com\/article\/3601554\/androxgh0st-botnet-integrates-mozi-payloads-to-target-iot-devices.html?utm=hybrid_search#:~:text=vulnerability%20in%20PHPUnit%20(-,CVE-2017-9841,-)%2C%20an%20automated%20testing\">CVE-2017-9841<\/a>, an almost decade-old critical remote code execution flaw in PHPUnit, remained top of the table with 4,201 recorded attacks, followed by <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-14028\" target=\"_blank\" rel=\"noopener\">CVE-2018-14028<\/a>, a failure to verify WordPress plugins as valid ZIP files (4,102), and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2018-20062\" target=\"_blank\" rel=\"noopener\">CVE-2018-20062<\/a>, a ThinkPHP remote code execution in NoneCms (3,482).<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <\/em><a href=\"https:\/\/www.infoworld.com\/article\/4222246\/exposed-vite-servers-are-being-probed-for-aws-and-azure-credentials.html\">InfoWorld<\/a><em>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Attackers have opened a new front in their war on software developers: Vite servers, which they are probing for sensitive data including cloud credentials, infrastructure configuration and environment files. Vite was created as a build tool for Vue, a JavaScript framework for building user interfaces and web applications, but has now become a widely used [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9496,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9495","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9495"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9495"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9495\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9496"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9495"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9495"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9495"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}