Known Vulnerable Dependency: vitest==4.0.18 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)
- Category
- Supply Chain
- Confidence
- 96% confidence
- Finding
vitest 4.0.18 is flagged for arbitrary file read and possible execution when the Vitest UI server is listening, plus the @vitest/mocker traversal issue. In this repository Vitest is only for testing, but if its UI/server features are enabled in development or CI and reachable by untrusted parties, an attacker could access sensitive files or trigger code execution paths.
- Content
