A security alert was published regarding CVE-2026-39365, a path traversal vulnerability affecting the Vite build tool (playground/fs_serve/node_modules/.vite/deps endpoint), which could potentially allow unauthorized disclosure of .map files. This alert has prompted inquiries regarding the impact on Service Virtualization (DevTest) environments.
Broadcom Engineering has conducted a comprehensive review of the Service Virtualization (DevTest) codebase and dependencies.
It has been confirmed that Service Virtualization (DevTest) is not impacted by CVE-2026-39365.
The vulnerability affects Vite versions 6.x, 7.x, and 8.x. Our analysis concluded the following:
bespin, phoenix, and dradis utilize alternative build tooling (rsbuild).keycloak-theme) is securely pinned to version 5.4.20. This version is significantly outside the range of affected versions (6.0.0 through 8.0.5).Required Action: No action, patching, or configuration changes are required. Customers may consider this vulnerability as "Not Applicable" to the DevTest product.