Vitest
This hub aggregates every CVE we track for Vitest, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
4
Critical
0
High
0
In CISA KEV
Severity distribution
CRITICAL4MEDIUM1
Monthly trend
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
2024-082026-07
Latest CVEs
The 5 most recently published vulnerabilities affecting Vitest.
- CVE-2026-53633Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE9.8
- CVE-2026-47428Vitest browser mode serves unsanitized otelCarrier query parameter as inline script9.6
- CVE-2026-47429Vitest: Arbitrary file can be read and executed when Vitest UI server is listening9.8
- CVE-2025-24963Browser mode serves arbitrary files in vitest5.9
- CVE-2025-24964Remote Code Execution when accessing a malicious website while Vitest API server is listening9.6
Product normalization is registry-driven with AI assist and human review. How it works