Known Vulnerable Dependency: vitest==1.2.0 — 1 advisory(ies): CVE-2025-24964 (Vitest allows Remote Code Execution when accessing a malicious website while Vit)
Critical
- Category
- Supply Chain
- Confidence
- 94% confidence
- Finding
- The package declares vitest version 1.2.0, which is flagged as having a known remote code execution vulnerability (CVE-2025-24964). Even though vitest is a devDependency, it can still be dangerous in developer workstations or CI environments where tests run and where malicious content may be accessed, potentially leading to code execution during development or testing workflows.
