Known Vulnerable Dependency: vitest==4.0.18 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)
Critical
- Category
- Supply Chain
- Confidence
- 90% confidence
- Finding
- vitest 4.0.18 is present with advisories for arbitrary file read and, in some configurations, file execution when the UI server is listening. Although Vitest is a dev dependency, the issue is real and can materially impact developer workstations or CI runners if test UI or mock features are exposed to untrusted input; the presence of related @vitest/mocker amplifies that risk.
