CVE-2026-47429

CRITICAL

Vitest: Arbitrary file can be read and executed when Vitest UI server is listening

Title source: cna
STIX 2.1

Description

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

Scores

CVSS v3 9.8
EPSS 0.0101
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
vitest-dev/vitest < 3.2.5
vitest-dev/vitest >= 4.0.0, < 4.1.0
Published Jul 14, 2026
Tracked Since Jul 15, 2026