CVE-2026-47429

🔴 Łataj teraz

Błąd w Vitest umożliwia atakującemu odczyt plików poza projektem oraz wykonanie dowolnych skryptów.

CVSS
9.8
EPSS
0.9%
Exploit
poc
Vendor
vitest.dev
Opis źródłowy (NVD)

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

exploit path-traversal Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.9%
Opublikowano (NVD)2026-07-14 20:17:02 UTC
Ostatnia modyfikacja (NVD)2026-08-06 18:25:42 UTC
Referencje