{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:694a09bb-6a29-5e4e-86bd-0cb9bf941c07",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-vite@4.5.5-tuxcare.4",
      "type": "library",
      "name": "create-vite",
      "version": "4.5.5-tuxcare.4",
      "purl": "pkg:npm/create-vite@4.5.5-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a07f06e2-50f6-52d6-87eb-4fffe17eee9a",
      "id": "CVE-2024-23331",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23331 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f04a905-7f2b-5f4a-bbb7-a6bc8a6f524e",
      "id": "CVE-2024-31207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31207 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31f0796a-f271-5981-b0c0-3b0b5a690921",
      "id": "CVE-2024-45811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-45811 does not affect version 4.5.5-tuxcare.4 of create-vite. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-45811. The fix is present in a semantically equivalent form, using `checkServingAccess` with `deniedServingAccessForTransform` instead of the vendor's `ensureServingAccess`, but providing identical protection against the ?import&raw bypass vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aa03c9b-c5e6-5ebb-9473-5a51bfcc03f5",
      "id": "CVE-2024-52011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52011 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3802460e-3157-5b08-9677-a9c6640135fb",
      "id": "CVE-2025-24010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24010 is fixed in version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4abd1fd7-0b1a-54e9-9125-65c6e4195139",
      "id": "CVE-2025-30208",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-30208 is fixed in version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee7ceefe-4cea-5f81-bf0c-76f9606795eb",
      "id": "CVE-2025-31125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31125 is fixed in version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fcf9b4d-b00d-5e90-9ed5-480178c76417",
      "id": "CVE-2025-31486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31486 is fixed in version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ab1d2e3-1bea-5048-84b3-03e077168fd4",
      "id": "CVE-2025-32395",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32395 is fixed in version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad6d23f-6a60-5ad9-b816-f22fc3dec856",
      "id": "CVE-2025-46565",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46565 is fixed in version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6096f73e-0798-5b5d-b48c-d32c089ede23",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58751 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd2d1d28-2875-5b22-8c10-8a31a35b781a",
      "id": "CVE-2025-58752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58752 is fixed in version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e65f4f11-b4f9-50e8-9f2c-588295aca90c",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62522 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae27bd85-eea7-5e56-93fb-b39f9c76eafe",
      "id": "CVE-2026-39363",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 4.5.5-tuxcare.4 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39363 does not affect Vite 4.5.5. The vulnerability requires fetchModule method and vite:invoke WebSocket event, which were introduced in later versions (5.x/6.x). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1f93ff9-0aea-537e-977a-99fc30cb9585",
      "id": "CVE-2026-39364",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39364 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87d25589-3416-55d4-9818-42329dffd7fc",
      "id": "CVE-2026-39365",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39365 does not affect version 4.5.5-tuxcare.4 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39365 path traversal vulnerability was present in the original Vite v4.5.5 but has been patched in version 4.5.5-tuxcare.7. The fix (commit 91f0a4f50, backported on 2026-04-20) adds validation to ensure .map file requests for optimized dependencies cannot traverse outside the optimized deps directory via '../' segments in the URL. The target repository currently includes this security patch. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48c564bd-7f4c-5b9d-90ee-63346bf6347c",
      "id": "CVE-2026-53571",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53571 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5f8b08d-efc4-52ac-8da2-13d59b28f526",
      "id": "CVE-2026-53632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53632 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5e21592-0489-5ccf-b7e3-85fd8f5f9bb5",
      "id": "GHSA-4w7w-66w2-5vf9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4w7w-66w2-5vf9 affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ffeb782-801b-51fc-a979-d250043b97c4",
      "id": "GHSA-v2wj-q39q-566r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v2wj-q39q-566r affects version 4.5.5-tuxcare.4 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-vite@4.5.5-tuxcare.4"
    }
  ]
}