Aller au contenu

Fiche vulnérabilité

CVE-2026-47429 : faille moyenne vitest.dev vitest (CVSS 5.9)

Description

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

En bref

Sévérité
Moyenne (CVSS 5.9)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
14 juil. 2026
Dernière mise à jour
6 août 2026

Produits concernés

  • vitest.dev vitest

Références

Rechercher une autre vulnérabilité dans la base CVE