Vitest
This hub aggregates every CVE we track for Vitest, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
5
Critical
0
High
0
In CISA KEV
Severity distribution
CRITICAL5MEDIUM2
Monthly trend
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
1
1
2024-102026-09
Latest CVEs
The 7 most recently published vulnerabilities affecting Vitest.
- CVE-2026-84373Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock5.9
- CVE-2026-73653Vitest: Browser Mode provider commands bypass the file-access permission gate9.4
- CVE-2026-53633Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE9.8
- CVE-2026-47428Vitest browser mode serves unsanitized otelCarrier query parameter as inline script9.6
- CVE-2026-47429Vitest: Arbitrary file can be read and executed when Vitest UI server is listening9.8
- CVE-2025-24963Browser mode serves arbitrary files in vitest5.9
- CVE-2025-24964Remote Code Execution when accessing a malicious website while Vitest API server is listening9.6
Product normalization is registry-driven with AI assist and human review. How it works