CRITICAL🇵🇱 Wersja polska

CVE-2026-47429

CVSS 9.8v3.1pub. 2026-07-14upd. 2026-08-06

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Vitest.dev Vitest

    APP
    Vitest.Dev
    < 3.2.54.0.0 – 4.1.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2025-24964CRITICAL9.6PL ✓same product

RCE w Vitest przez Cross-site WebSocket Hijacking (CSWSH)

CVE-2025-24963MEDIUM5.9same product

Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP serve...