CRITICAL9.8npm
GHSA-5xrq-8626-4rwp· CVE-2026-47429When Vitest UI server is listening, arbitrary file can be read and executed
Modified: 9/10/2026
package
pkg:npm/vitest
When Vitest UI server is listening, arbitrary file can be read and executed
Modified: 9/10/2026
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
Modified: 9/8/2026
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Modified: 2/4/2025