← All articles

Mass scanning hunts exposed Vite dev servers for cloud credentials and secrets

Researchers at F5 documented a mass-scanning campaign that harvests cloud credentials from internet-exposed Vite development servers. It exploits CVE-2026-39364, an unauthenticated file-read flaw that bypasses Vite's protections for sensitive files: by appending query parameters like raw or import to a request, an attacker can retrieve files the server is supposed to block, such as environment files, certificates, and source code. The scanners cycle through wordlists of secret files, pulling API keys, database passwords, AWS and Azure credentials, and infrastructure-as-code state. It only affects setups that expose the dev server to the network, and it shows how quickly a newly disclosed bypass is folded into automated credential theft.

Check
Never expose a Vite or other development server to the internet, update Vite, and rotate any secrets, cloud keys, or state files an exposed dev server could have leaked.
Affected
Teams running internet-exposed Vite development servers on vulnerable versions (CVE-2026-39364); attackers can read blocked files to steal environment secrets, AWS and Azure credentials, and infrastructure-as-code state, without any authentication.
Fix
Keep dev servers bound to localhost and off the public internet, patch Vite, scan your external attack surface for exposed dev tooling, rotate leaked secrets, and treat exposed dev environments as targets.