Vite CVE-2026-39364: Mass Scanners Harvest Cloud Credentials and Terraform State From Exposed Dev Servers (F5 Labs) — Proactive DLP Flags Secrets in Config Files Before They Cross the Boundary (2026-09-15 CISO Daily Digest)
The 2026-09-15 CISO Daily Digest covered F5 Labs' documentation of an August 2026 mass-scanning campaign against internet-exposed Vite development servers attacking CVE-2026-39364 (CVSS 8.2): a query-parameter bypass of Vite's server.fs.deny protection, where the ?raw, ?import&raw and ?import&url&inline variants return files the server is supposed to block. The scanners drive requests at the /@fs/ endpoint to pull .env files, AWS and Azure credentials, configurations and backups, terraform.tfstate and serverless.yml state files, and /proc/self/environ — all in cleartext — while impersonating crawler and AI-bot user agents (Googlebot, ClaudeBot, GPTBot, PerplexityBot, OAI-SearchBot and Amazonbot) and forging X-Forwarded-For/X-Real-IP values to slip past IP allowlists and muddy log analysis. Significant scan activity originated from the U.S., Belgium, the Netherlands, Singapore and Taiwan, including Google Cloud IP ranges; only deployments explicitly exposed via --host / server.host (or container port-mapping mistakes) are reachable — by default Vite binds to localhost. The failure mode is a classic one: the secrets live in files (.env, state files, configs), and once a file crosses a boundary — a dev-server response, an upload, an email attachment — there is no second line of defense. This demo ships the credential-bearing config file as a synthetic stand-in: malicious-config.py carries hardcoded API key and database-password patterns (synthetic values only — nothing executes, safe to open anywhere), and clean-config.py shows the remediated version that reads the same values from environment variables. MetaDefender Proactive DLP inspects file content — not just names or extensions — detects credential patterns (API-key formats, password assignments, secrets in config and state files) and blocks, quarantines or alerts before this material leaves the organization (MITRE ATT&CK T1552.001 — Unsecured Credentials: Credentials In Files).
Attack Technique
Exposed Vite dev-server file disclosure (CVE-2026-39364) — mass scanners request the /@fs/ endpoint to fetch .env files, cloud credentials and terraform.tfstate in cleartext; the demo shows the secret-bearing config file that Proactive DLP must catch (T1552.001 Unsecured Credentials: Credentials In Files)
MITRE ATT&CK
T1552.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗