Vitest.dev
Vitest.dev Vitest: vulnerabilities and CVEs
Vitest.dev Vitest has 7 published vulnerabilities, 5 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months5
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84373 | Medium (5.9) | 0.53% | — | Sep 1, 2026 | Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the… |
| CVE-2026-73653 | Critical (9.4) | 0.79% | — | Aug 13, 2026 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and… |
| CVE-2026-53633 | Critical (9.8) | 0.90% | — | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by… |
| CVE-2026-47429 | Medium (5.9) | 0.88% | — | Jul 14, 2026 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read… |
| CVE-2026-47428 | Critical (9.6) | 0.61% | — | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script,… |
| CVE-2025-24964 | High (8.8) | 0.68% | — | Feb 4, 2025 | Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking… |
| CVE-2025-24963 | High (7.5) | 2.4% | — | Feb 4, 2025 | Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.