Known Vulnerable Dependency: vitest==1.6.1 — 1 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed)
- Category
- Supply Chain
- Confidence
- 91% confidence
- Finding
Vitest 1.6.1 is flagged for arbitrary file read and execution when the Vitest UI server is listening. Although this is a dev dependency rather than application runtime code, a vulnerable test UI exposed on a developer machine or CI environment could enable serious compromise of local files or code execution.
- Content
