Skip to content

[Security] vitest >=4.0.0 <4.1.0 — When Vitest UI server is listening, arbitrary file can be read and executed #83

Description

@bitskc

Dependency Vulnerability

Package: vitest
Severity: critical
Advisory: When Vitest UI server is listening, arbitrary file can be read and executed
Advisory URL: GHSA-5xrq-8626-4rwp
Affected Range: >=4.0.0 <4.1.0

Description

When Vitest UI server is listening, arbitrary file can be read and executed

Fix Recommendation

Run npm audit fix to resolve


This issue was automatically created by a dependency vulnerability scan.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions