Known Vulnerable Dependency: vitest==4.0.18 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)
Critical
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
- vitest 4.0.18 is a genuinely vulnerable version with advisories for arbitrary file read and, in some configurations, code execution through Vitest UI or mocking features. Even though it is a dev dependency, the skill context is security-oriented and may encourage running scans/tests in automated or semi-exposed environments, which increases the chance that unsafe test infrastructure could be reachable or process untrusted content.
