{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7953cd6d-be5c-5299-8ebb-e002671ad764",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-vite@4.5.5-tuxcare.5",
      "type": "library",
      "name": "create-vite",
      "version": "4.5.5-tuxcare.5",
      "purl": "pkg:npm/create-vite@4.5.5-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:411a92e6-691c-5e4e-8c6f-531ec5d8b8d6",
      "id": "CVE-2024-23331",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23331 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ea3112c-18e9-5c22-a011-946932f43e1e",
      "id": "CVE-2024-31207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31207 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:648d833c-9c47-5625-b41d-0a193713356d",
      "id": "CVE-2024-45811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-45811 does not affect version 4.5.5-tuxcare.5 of create-vite. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-45811. The fix is present in a semantically equivalent form, using `checkServingAccess` with `deniedServingAccessForTransform` instead of the vendor's `ensureServingAccess`, but providing identical protection against the ?import&raw bypass vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f66a8ebe-523a-542d-9ac4-5350c3cff94b",
      "id": "CVE-2024-52011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52011 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9820a8c0-a2d5-549f-9d41-a2da9838de20",
      "id": "CVE-2025-24010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24010 is fixed in version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e71cdfd-6e8b-5603-9724-e28c4d4c60db",
      "id": "CVE-2025-30208",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-30208 is fixed in version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde94346-2fcd-5b42-8f46-50546ab15a8e",
      "id": "CVE-2025-31125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31125 is fixed in version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:975e01a7-f82e-5c9f-aa34-5e4bf248efd8",
      "id": "CVE-2025-31486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31486 is fixed in version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205be3eb-12ea-572d-ab13-a3fe2143f5db",
      "id": "CVE-2025-32395",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32395 is fixed in version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5e7d03-37e5-59d2-801b-b02e74ec3f13",
      "id": "CVE-2025-46565",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46565 is fixed in version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b789b1-3be4-5141-957a-3fc4f9fff9bf",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58751 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e88a1a-a0c6-5852-93d9-5e6d669491b7",
      "id": "CVE-2025-58752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58752 is fixed in version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737bd24f-09ef-5dbf-9c6a-b87e9742fc75",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62522 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:467489b0-7b26-584a-b612-64083ae1e086",
      "id": "CVE-2026-39363",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 4.5.5-tuxcare.5 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39363 does not affect Vite 4.5.5. The vulnerability requires fetchModule method and vite:invoke WebSocket event, which were introduced in later versions (5.x/6.x). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26dc4fbf-107f-5257-ad82-c7bbf1f1e4e2",
      "id": "CVE-2026-39364",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39364 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:453bdfb3-86a4-5046-82f7-4787d8160b23",
      "id": "CVE-2026-39365",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39365 does not affect version 4.5.5-tuxcare.5 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39365 path traversal vulnerability was present in the original Vite v4.5.5 but has been patched in version 4.5.5-tuxcare.7. The fix (commit 91f0a4f50, backported on 2026-04-20) adds validation to ensure .map file requests for optimized dependencies cannot traverse outside the optimized deps directory via '../' segments in the URL. The target repository currently includes this security patch. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9b64719-d05e-5b53-a32d-2c399106bdc8",
      "id": "CVE-2026-53571",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53571 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42214329-d673-547a-8014-bf8020337a98",
      "id": "CVE-2026-53632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53632 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79bd62cf-a5b4-5993-b37f-5018b1dc75fd",
      "id": "GHSA-4w7w-66w2-5vf9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4w7w-66w2-5vf9 affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:987456f0-5713-532a-a9f2-055932f8b623",
      "id": "GHSA-v2wj-q39q-566r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v2wj-q39q-566r affects version 4.5.5-tuxcare.5 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-vite@4.5.5-tuxcare.5"
    }
  ]
}