# vite@8.3.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:25:16.000Z
- Files reviewed: 13
- Findings: 3 medium, 12 low severity findings
- Report: https://security.togoder.click/npm/vite
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package vite@8.3.2 on Oct 6, 2026. An AI review of 13 source files produced 3 medium, 12 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-D85EB2E98C36`

File: `dist/node/module-runner.js`

The ESModulesEvaluator class uses `new AsyncFunction(...)` to execute module code dynamically via `runInlinedModule`. This constructs and runs a function at runtime from string input, which is a known pattern for arbitrary code execution if the code source is not fully trusted.

### [medium] Dynamic module loading

Finding ID: `NPS-FF3D78986749`

File: `dist/node/module-runner.js`

`ESModulesEvaluator.runExternalModule(filepath)` calls `import(filepath)` where `filepath` is derived from server-fetched module metadata (`fetchedModule.externalize`). This dynamic import of a computed value could load arbitrary modules if the transport source is untrusted.

### [medium] Dynamic import registration

Finding ID: `NPS-36C0DAE8BED3`

File: `dist/node/module-runner.js`

`createImportMetaResolver()` calls `module.register(hookModuleContent)` and `module.registerHooks(...)` to register a custom module resolution hook at runtime, altering Node's module resolution behavior.

### [low] top-level code execution

Finding ID: `NPS-795B078C40C7`

File: `bin/vite.js:1`

Top-level code runs at import/execution time, including setting a global start time, parsing debug/profile arguments, and invoking start(), which is normal for a CLI shim.

### [low] compile cache manipulation

Finding ID: `NPS-AD98FE6B26DC`

File: `bin/vite.js:68`

module.enableCompileCache and module.flushCompileCache are used to improve startup performance. These are Node built-ins and do not indicate malicious behavior.

### [low] dynamic import

Finding ID: `NPS-1D3D44C87DA8`

File: `bin/vite.js:78`

The script dynamically imports '../dist/node/cli.js' relative to the launcher, which is expected behavior for a CLI entry point and not externally controlled.

### [low] inspector/profiler usage

Finding ID: `NPS-69DBD8C8CF71`

File: `bin/vite.js:88`

When --profile is passed, the script enables Node's inspector and starts CPU profiling. This is a documented Vite feature and does not exfiltrate data or execute untrusted code.

### [low] Dynamic code execution

Finding ID: `NPS-00B300130403`

File: `dist/client/env.mjs:6`

Uses Function("return this")() as a fallback to obtain the global object. While this is a common pattern for cross-environment global detection, it constitutes dynamic code execution and can be blocked by strict Content Security Policy (CSP) environments.

### [low] Global object pollution

Finding ID: `NPS-889140FCD4DF`

File: `dist/client/env.mjs:8`

Iterates over keys in __DEFINES__ and writes values onto the global context (globalThis/window/self). Nested keys create or mutate global objects. This could be abused to overwrite security-sensitive globals if __DEFINES__ is attacker-controlled or misconfigured, though typically it is a compile-time constant injected by the bundler.

### [low] File system manipulation outside package scope

Finding ID: `NPS-53D3EB368EE3`

File: `dist/node/cli.js`

The stopProfiler function writes CPU profile files to the current working directory using fs.writeFileSync with a path resolved from the current directory (path.resolve('./${fileName}.cpuprofile')). While this is standard behavior for Vite's profiling feature and the filename is controlled via a global variable, writing files to the CWD based on an environment-controlled global (global.__vite_profile_name) could potentially be abused if that global is set to a path traversal value, though path.resolve would still constrain to CWD-relative paths in most cases.

### [low] Dynamic imports based on internal module paths

Finding ID: `NPS-93A04DE10561`

File: `dist/node/cli.js`

Multiple dynamic imports are used (import('./chunks/node.js'), import('node:inspector')) to lazily load modules. These are resolved from static string literals and internal relative paths, not from external or computed input, so risk is minimal. However, the pattern of dynamic module loading is worth noting.

### [low] Global state mutation via process globals

Finding ID: `NPS-5E7539FCAB9A`

File: `dist/node/cli.js`

Reads and writes to global.__vite_profile_session and global.__vite_profile_name, which influence profiler file naming. If external code can manipulate these globals (e.g., via a malicious config), it could influence file paths. No credential harvesting or exfiltration is present.

### [low] JSON parsing of remote/transformed content

Finding ID: `NPS-A99886BC0094`

File: `dist/node/module-runner.js`

Source maps are extracted from module code via regex and parsed with `JSON.parse(decodeBase64(...))` in `getModuleSourceMapById`, and later `new DecodedMap(...)` operates on that data. This is generally expected behavior for a module runner, but parsing external data is a potential vector.

### [low] Dynamic RPC/transport invocation

Finding ID: `NPS-1CF08B11F3C1`

File: `dist/node/module-runner.js`

The `createInvokeableTransport` and `normalizeModuleRunnerTransport` implement an RPC mechanism over the transport (`vite:invoke`), and `getModuleInformation` invokes `fetchModule` with URL/importer arguments. This is network-based code loading driven by computed values, which is a pattern to verify carefully against the package's stated purpose.

### [low] Sourcemap interceptor / Error.prepareStackTrace override

Finding ID: `NPS-DE1657BBBC90`

File: `dist/node/module-runner.js`

`interceptStackTrace` overrides `Error.prepareStackTrace` globally, which can affect diagnostics and is an invasive runtime change, though common for sourcemap tooling.

## Files reviewed

- `dist/client/env.mjs` (medium): Code performs runtime global-object detection using Function() and injects build-time defines onto the global scope, but shows no evidence of data exfiltration, credential harvesting, or other malicious behavior.
- `dist/node/cli.js` (medium): This appears to be the legitimate Vite CLI entry point with standard dev server, build, optimize, and preview commands; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected, though minor filesystem writes to CWD and dynamic imports warrant low-severity notes.
- `dist/node/module-runner.js` (medium): This is Vite's module-runner implementation that legitimately uses new AsyncFunction, dynamic import, and RPC transport to execute transformed modules; the patterns are consistent with its documented role but do involve dynamic code execution and dynamic module loading that carry inherent risk if the transport source is untrusted.
- `bin/openChrome.js` (safe): Legitimate macOS JXA script from create-react-app for opening URLs in Chrome, with no malicious patterns detected.
- `bin/vite.js` (safe): The file is a standard Vite CLI launcher with development-oriented flags and no signs of malicious behavior such as data exfiltration, credential harvesting, obfuscation, mining, backdoors, or suspicious process spawning.
- `dist/client/bundledDevClient.mjs` (safe): This is a standard Vite HMR client bundle with no malicious patterns detected.
- `dist/client/client.mjs` (safe): This is the standard Vite HMR client runtime; no malicious patterns, exfiltration, credential harvesting, or unauthorized code execution were detected.
- `dist/node/chunks/lib.js` (safe): No malicious patterns detected; the file is a bundled copy of the benign postcss-value-parser library with no network, filesystem, process execution, or obfuscated code.
- `dist/node/chunks/postcss-import.js` (safe): The code is a bundled copy of the legitimate postcss-import package (v16.2.0) that performs CSS @import resolution and inlining with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, network exfiltration, or process spawning.
- `dist/node/index.js` (safe): The file is a standard Vite distribution re-export module containing only imports and exports of legitimate build-tool APIs, with no malicious patterns, obfuscation, dynamic code execution, or suspicious network/file/process activity.
- `dist/node/internal.js` (safe): No malicious patterns detected
- `misc/false.js` (safe): Cleared by Jev triage; no further analysis needed
- `misc/true.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
