{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a7c6d8f4-82f6-58e0-93b8-e6622b7b553f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-vite@4.5.5-tuxcare.8",
      "type": "library",
      "name": "create-vite",
      "version": "4.5.5-tuxcare.8",
      "purl": "pkg:npm/create-vite@4.5.5-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c63aec78-a11c-5eaf-9635-ef83c08eee21",
      "id": "CVE-2024-23331",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23331 affects version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eaadd23-a4d6-58d3-b643-e01a3eb85475",
      "id": "CVE-2024-31207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31207 affects version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:319c521e-8cfa-5cf3-9f99-33719b127666",
      "id": "CVE-2024-45811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-45811 does not affect version 4.5.5-tuxcare.8 of create-vite. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-45811. The fix is present in a semantically equivalent form, using `checkServingAccess` with `deniedServingAccessForTransform` instead of the vendor's `ensureServingAccess`, but providing identical protection against the ?import&raw bypass vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec2a5443-4f28-51d9-9282-a91ae3734ff2",
      "id": "CVE-2024-52011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52011 affects version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3eba0ce1-e136-5575-a9bb-c4c62b16c14a",
      "id": "CVE-2025-24010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24010 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98b5bab3-d339-5873-8925-33a2ec45d79b",
      "id": "CVE-2025-30208",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-30208 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c93ea6-1af3-59ac-9861-39c0bb29113c",
      "id": "CVE-2025-31125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31125 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37312860-3cf7-5da9-b92c-c9c5d833bbc0",
      "id": "CVE-2025-31486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31486 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae1d7338-483a-59b1-be48-95965f049981",
      "id": "CVE-2025-32395",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32395 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:053046cd-8d23-58d3-8a6f-07293b49cb14",
      "id": "CVE-2025-46565",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46565 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1371c0b6-fe5f-533c-a900-17bbcdf158de",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58751 affects version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de3451d3-0300-5bf9-a3a9-3295ed7ba88e",
      "id": "CVE-2025-58752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58752 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45f74e4e-b8f1-5e62-828f-e7f3be698431",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62522 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6255c95-6792-5a25-a3bb-69cd17181481",
      "id": "CVE-2026-39363",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 4.5.5-tuxcare.8 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39363 does not affect Vite 4.5.5. The vulnerability requires fetchModule method and vite:invoke WebSocket event, which were introduced in later versions (5.x/6.x). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24bd56a7-f090-5abf-baf5-4d51e9203b5c",
      "id": "CVE-2026-39364",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39364 affects version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d107d145-f2bc-5c49-a3b4-195725f172fa",
      "id": "CVE-2026-39365",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39365 does not affect version 4.5.5-tuxcare.8 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39365 path traversal vulnerability was present in the original Vite v4.5.5 but has been patched in version 4.5.5-tuxcare.7. The fix (commit 91f0a4f50, backported on 2026-04-20) adds validation to ensure .map file requests for optimized dependencies cannot traverse outside the optimized deps directory via '../' segments in the URL. The target repository currently includes this security patch. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7328f753-14b2-562c-8b7c-df9190e6cb1d",
      "id": "CVE-2026-53571",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53571 affects version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55ef38e3-6660-5f6e-b225-1e8786985b74",
      "id": "CVE-2026-53632",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53632 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e02a0c4c-7fdf-5acc-affa-2ac033291eb9",
      "id": "GHSA-4w7w-66w2-5vf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4w7w-66w2-5vf9 is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f19b43e-b3b1-5d4c-a6db-5c2791a4df85",
      "id": "GHSA-v2wj-q39q-566r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v2wj-q39q-566r is fixed in version 4.5.5-tuxcare.8 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-vite@4.5.5-tuxcare.8"
    }
  ]
}