Known Vulnerable Dependency: vitest==4.0.18 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)
Critical
- Category
- Supply Chain
- Confidence
- 93% confidence
- Finding
- vitest 4.0.18 is reported vulnerable to arbitrary file read and, in some configurations, file execution through its UI server and mocker integration. In this skill it is a testing dependency, not part of the intended runtime, which reduces direct end-user exposure, but it remains dangerous in developer/CI environments if the UI server or untrusted test assets are used.
