{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bc1da7d8-6e29-5e5f-9c5d-04c42191be5c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-vite@4.5.14-tuxcare.3",
      "type": "library",
      "name": "create-vite",
      "version": "4.5.14-tuxcare.3",
      "purl": "pkg:npm/create-vite@4.5.14-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d0a72aff-b4d0-5567-b120-7e2d90d07dda",
      "id": "CVE-2024-23331",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-23331 does not affect version 4.5.14-tuxcare.3 of create-vite. already_fixed \u2014 The target repository (Vite 4.5.14-tuxcare.1) already contains the fix for CVE-2024-23331. The vulnerability allowed bypassing server.fs.deny restrictions on case-insensitive filesystems by using case-augmented filenames (e.g., .EnV instead of .env). The fix adds nocase: true to the picomatch configuration, enabling case-insensitive glob pattern matching that blocks such bypass attempts."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:689aeefa-f35e-52c5-b9fb-835de158f43b",
      "id": "CVE-2024-31207",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-31207 does not affect version 4.5.14-tuxcare.3 of create-vite. already_fixed \u2014 CVE-2024-31207 has already been fixed in the target repository. The fix from upstream commit 96a7f3a41 is present at packages/vite/src/node/server/index.ts lines 518-530. The vulnerability (bypass of directory-based fs.deny patterns due to picomatch misconfiguration) was fixed by changing matchBase from true to false, adding dot: true, and normalizing patterns without directory separators."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7356d887-dad3-51f1-ba0d-eecfbbadebdb",
      "id": "CVE-2024-45811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-45811 does not affect version 4.5.14-tuxcare.3 of create-vite. already_fixed \u2014 CVE-2024-45811 has been fixed in the target repository. The fix was backported in commit b901438f9 (Sep 16, 2024) and is present in version 4.5.14-tuxcare.1. The current implementation uses deniedServingAccessForTransform to validate access before serving files with raw/url query parameters, preventing unauthorized file access outside the serving allow list."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:055993e9-aea3-5d6e-be46-355b3e65f24b",
      "id": "CVE-2024-52011",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52011 is fixed in version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19d1d146-7f67-5cec-9b2a-09797c520b7c",
      "id": "CVE-2025-24010",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-24010 does not affect version 4.5.14-tuxcare.3 of create-vite. already_fixed \u2014 All three CVE-2025-24010 vulnerabilities (permissive CORS, missing WebSocket Origin validation, missing Host header validation) have been fixed in the target repository at commit aa7b8e80132745520acb694f2d65064bd0dfe524. The fixes were applied via commits c065a775d (WebSocket token), ef1049d45 (Host header), and 07b36d503 + 8f63cd66a (CORS restrictions) on 2025-01-20, before the current 4.5.14-..."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4065320e-135c-58be-a955-3ab188bea0c8",
      "id": "CVE-2025-46565",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46565 affects version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18247422-097a-539a-b2c8-a895b3ca2a32",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58751 is fixed in version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea291bc-c347-5115-9e77-b8435a60c810",
      "id": "CVE-2025-58752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58752 is fixed in version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7146d00-4d79-5c3c-9d48-a4e43aa7ef55",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62522 is fixed in version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e69f2395-3fcb-5f8b-842c-443be3966012",
      "id": "CVE-2026-39363",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 4.5.14-tuxcare.3 of create-vite. not_affected \u2014 Vite 4.5.14 is not affected by CVE-2026-39363. The vulnerability describes a WebSocket fetchModule API that bypasses server.fs access controls, but this API does not exist in version 4.5.14. The fetchModule feature was introduced 1,481 commits later in Vite 6.0.0-beta.9. The target version's WebSocket implementation only supports HMR payloads and a single custom event (vite:invalidate) for modu..."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f017eee9-e25d-59ba-b6ef-75754666b719",
      "id": "CVE-2026-39364",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39364 does not affect version 4.5.14-tuxcare.3 of create-vite. not_affected \u2014 The target Vite version 4.5.14 is not affected by CVE-2026-39364. The vulnerability exists in versions 7.1.0 through 7.3.1 and 8.0.0 through 8.0.4, where a code refactoring introduced a flaw allowing server.fs.deny bypass via query parameters. Version 4.5.14 uses a different architectural approach that includes query parameter stripping before access control checks, preventing the attack."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b4e69ef-3def-5ce9-9673-df01a2762049",
      "id": "CVE-2026-39365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-39365 is fixed in version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65000754-4d83-5611-853b-2d118c75fadd",
      "id": "CVE-2026-53571",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53571 affects version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76a7da0d-b089-5f0b-8bf3-611b10d0e425",
      "id": "CVE-2026-53632",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53632 is fixed in version 4.5.14-tuxcare.3 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-vite@4.5.14-tuxcare.3"
    }
  ]
}