{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:faeb6801-eb7a-5b2e-a001-db4c130a5f97",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "create-vite",
      "purl": "pkg:npm/create-vite@3.2.11-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/create-vite@3.2.11-tuxcare.6",
      "version": "3.2.11-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-23331",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8f72d9a7-388c-5225-a52f-3355e9c1c8e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23331 affects version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2024-31207",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:64f2797f-91f5-5f0f-a435-0e3d0e534f1f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-31207 does not affect version 3.2.11-tuxcare.6 of create-vite. Version 3.2.11 is not vulnerable. Summary: The target repository (Vite v3.2.11) is NOT vulnerable to CVE-2024-31207. The vulnerability was introduced in v3.2.0 (commit df560b02d, 2022-09-22) and fixed in v3.2.9 (commit 89c7c645f, 2024-03-24). The current version includes the complete fix that properly handles server.fs.deny patterns with directories. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-45811",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ccb4f18a-d46a-5179-9d14-da764b2db073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45811 affects version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2024-52011",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a598c98b-6c08-53ec-8f0a-23d8a85539f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52011 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-24010",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a9a8b45f-30ac-513d-a6d8-bd57b5fb42ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24010 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-30208",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fc241f0a-4281-5e88-b2a2-b5864cdf4147",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-30208 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-31125",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5942ae55-0404-5321-bb25-e52176253e41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31125 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-31486",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8771468f-721a-5a0d-94b1-648ba9e7c592",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31486 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-32395",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ca1cb0a9-2918-5c43-b893-c7169e14088e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32395 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-46565",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:905caaf9-b6be-55d1-a4d8-7c719bdd4818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46565 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-58751",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8ded0c75-4b69-57cb-a39d-e85e247b9eda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58751 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-58752",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f43abf14-65a0-547b-aeea-08b1a7237e85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58752 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2025-62522",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:baa961c8-ad30-5aa4-9ba8-826b89cff552",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62522 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2026-39363",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6ee80cb8-c57f-5770-8ea5-e040c3c493a3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 3.2.11-tuxcare.6 of create-vite. Version 3.2.11 is not vulnerable. Summary: Target repository (Vite 3.2.11-tuxcare.1) predates the introduction of the vulnerable feature. The fetchModule method exposed via WebSocket (vite:invoke event) does not exist in this version. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-39364",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6073170d-1a29-5f6d-8c22-820956c4bb63",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39364 does not affect version 3.2.11-tuxcare.6 of create-vite. CVE-2026-39364 affects Vite versions 7.1.0 through 7.3.1 and 8.0.0 through 8.0.4. Version 3.2.11 predates the vulnerable architecture introduced in v7.1.0. The v3.2.11 codebase already strips query parameters via fsPathFromUrl()->cleanUrl() before checking server.fs.deny patterns, preventing the bypass described in the CVE. The attack chain (module IDs with query parameters bypassing deny checks) requires the v7+ architecture and does not apply to the older v3.2.11 implementation.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-39365",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0b276e79-3003-570b-bea4-ffcd7bc3f5e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-39365 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2026-53571",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:adde3472-4a87-5ca5-b9fd-9e13afb96fdc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53571 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    },
    {
      "id": "CVE-2026-53632",
      "affects": [
        {
          "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e993d9ec-dcd2-5052-8d42-7fb4f71a0a38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53632 is fixed in version 3.2.11-tuxcare.6 of create-vite."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-vite@3.2.11-tuxcare.6"
    }
  ]
}