Vulnerabilities
Summary — last 7 days
New vulnerabilities2,751▲ 29 vs. last week
Critical / high1,468▲ 334 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
7 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.9) | 0.53% | — | Vitest.dev VitestAI | 9/1/2026 | 9/9/2026 | Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:register handler on Vite's unauthenticated HMR WebSocket without validating redirect… | |
| Deferred | Critical (9.4) | 0.79% | — | Vitest.dev VitestAI | 8/13/2026 | 9/9/2026 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or… | |
| Awaiting Analysis | Critical (9.8) | 0.90% | — | Vitest.dev VitestAI | 7/14/2026 | 7/29/2026 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP… | |
| Analyzed | Medium (5.9) | 0.88% | — | Vitest.dev Vitest | 7/14/2026 | 8/6/2026 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could… | |
| Deferred | Critical (9.6) | 0.61% | — | Vitest.dev VitestAI | 7/14/2026 | 7/15/2026 | Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin… | |
| Analyzed | High (8.8) | 0.68% | — | Vitest.dev Vitest | 2/4/2025 | 6/17/2026 | Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. When `api` option is enabled (Vitest UI enables it), Vitest starts a WebSocket… | |
| Analyzed | High (7.5) | 2.4% | — | Vitest.dev Vitest | 2/4/2025 | 6/17/2026 | Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by `browser.api.host: true`, an attacker can send a request to that handler from remote to get the content of… |