CVE-2026-47429
🔴 Łataj teraz
Błąd w Vitest umożliwia atakującemu odczyt plików poza projektem oraz wykonanie dowolnych skryptów.
CVSS
9.8
EPSS
0.9%
Exploit
poc
Vendor
vitest.dev
Opis źródłowy (NVD)
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.
exploit path-traversal
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.9% |
| Opublikowano (NVD) | 2026-07-14 20:17:02 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-06 18:25:42 UTC |
Referencje
- https://github.com/vitest-dev/vitest/commit/20e00ef7808de6d330c5e2fda530f686e08f1c8d (security-advisories@github.com) [Patch]
- https://github.com/vitest-dev/vitest/commit/af88b1f5d82844a4761ea9a977156c98e2b14ca8 (security-advisories@github.com) [Patch]
- https://github.com/vitest-dev/vitest/pull/10445 (security-advisories@github.com) [Exploit, Issue Tracking, Patch]
- https://github.com/vitest-dev/vitest/pull/9350 (security-advisories@github.com) [Exploit, Issue Tracking, Patch]
- https://github.com/vitest-dev/vitest/releases/tag/v3.2.5 (security-advisories@github.com) [Release Notes]
- https://github.com/vitest-dev/vitest/releases/tag/v4.1.0 (security-advisories@github.com) [Release Notes]
- https://github.com/vitest-dev/vitest/security/advisories/GHSA-5xrq-8626-4rwp (security-advisories@github.com) [Exploit, Mitigation, Vendor Advisory]