« Back to list

Vitest.dev

Vitest.dev Vitest: vulnerabilities and CVEs

Vitest.dev Vitest has 7 published vulnerabilities, 5 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months5
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-84373Medium (5.9)0.53%—Sep 1, 2026
Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the…
CVE-2026-73653Critical (9.4)0.79%—Aug 13, 2026
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and…
CVE-2026-53633Critical (9.8)0.90%—Jul 14, 2026
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by…
CVE-2026-47429Medium (5.9)0.88%—Jul 14, 2026
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read…
CVE-2026-47428Critical (9.6)0.61%—Jul 14, 2026
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script,…
CVE-2025-24964High (8.8)0.68%—Feb 4, 2025
Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking…
CVE-2025-24963High (7.5)2.4%—Feb 4, 2025
Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter2
  4. T1059.007 JavaScript1
  5. T1189 Drive-by Compromise1
  6. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.