{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:55871a10-6ffc-5266-9380-fb307f1b34bd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-vite@3.2.11-tuxcare.1",
      "type": "library",
      "name": "create-vite",
      "version": "3.2.11-tuxcare.1",
      "purl": "pkg:npm/create-vite@3.2.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d786dda7-6d32-5a9f-a40c-281937d9b465",
      "id": "CVE-2024-23331",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23331 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bed9b815-2434-5eab-960c-95e445facfea",
      "id": "CVE-2024-31207",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-31207 does not affect version 3.2.11-tuxcare.1 of create-vite. Version 3.2.11 is not vulnerable. Summary: The target repository (Vite v3.2.11) is NOT vulnerable to CVE-2024-31207. The vulnerability was introduced in v3.2.0 (commit df560b02d, 2022-09-22) and fixed in v3.2.9 (commit 89c7c645f, 2024-03-24). The current version includes the complete fix that properly handles server.fs.deny patterns with directories. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:018f9c47-2365-56eb-ac8e-57e80e97a247",
      "id": "CVE-2024-45811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45811 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4082ae4-d8e5-5331-8009-3235f54f7d44",
      "id": "CVE-2024-52011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52011 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9ac8dd7-ebab-53a4-96a1-dd6b5f79c101",
      "id": "CVE-2025-24010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24010 is fixed in version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f154820f-065d-5936-a09d-d1924eca246c",
      "id": "CVE-2025-30208",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-30208 is fixed in version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f840ed5-7aa4-5905-8489-edd2447e943f",
      "id": "CVE-2025-31125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31125 is fixed in version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc44f703-3355-50bf-b788-577b855d6a15",
      "id": "CVE-2025-31486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31486 is fixed in version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fa626cc-1cbb-54d0-91f0-906641d3c4ce",
      "id": "CVE-2025-32395",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32395 is fixed in version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db03daa2-bb29-5c83-8be9-0f5a3926d963",
      "id": "CVE-2025-46565",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46565 is fixed in version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62fabb78-4838-5f16-9c11-950575aa49fc",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58751 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74baa3f9-fc54-5f68-94b7-9d2a3dfae5a1",
      "id": "CVE-2025-58752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58752 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a976f0-4e6e-5187-839e-c06465deba3f",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62522 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28800624-9d8e-538a-b0d2-048d1df835fe",
      "id": "CVE-2026-39363",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 3.2.11-tuxcare.1 of create-vite. Version 3.2.11 is not vulnerable. Summary: Target repository (Vite 3.2.11-tuxcare.1) predates the introduction of the vulnerable feature. The fetchModule method exposed via WebSocket (vite:invoke event) does not exist in this version. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:763522ca-814e-581f-a9f1-955432f96689",
      "id": "CVE-2026-39364",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39364 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd238c44-356b-5761-b6b9-f4ac6716f02e",
      "id": "CVE-2026-39365",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39365 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5913d5c6-0deb-54a2-963e-4e1c426b4c6d",
      "id": "CVE-2026-53571",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53571 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bfe7b42-f06e-5140-a9be-46d6b6c61c49",
      "id": "CVE-2026-53632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53632 affects version 3.2.11-tuxcare.1 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-vite@3.2.11-tuxcare.1"
    }
  ]
}