CVE-2026-47429
- EPSS 0.92%
- Veröffentlicht 14.07.2026 19:28:08
- Zuletzt bearbeitet 06.08.2026 18:25:42
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; expose...
CVE-2025-24963
- EPSS 2.34%
- Veröffentlicht 04.02.2025 20:15:50
- Zuletzt bearbeitet 31.12.2025 14:44:35
Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by `browser.api.host: true`, an attacker can...
CVE-2025-24964
- EPSS 0.68%
- Veröffentlicht 04.02.2025 20:15:50
- Zuletzt bearbeitet 31.12.2025 14:50:11
Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. When `api` opti...