Package: vitest
Ecosystem: npm
Affected versions: >=4.0.0 <4.1.0
Severity: critical
CVSS Score: 9.8
Description
When Vitest UI server is listening, arbitrary file can be read and executed
Advisory
GHSA-5xrq-8626-4rwp
Fix Recommendation
A fix is available. Run npm audit fix to update affected dependencies, or manually update vitest to the latest patched version.
This issue was automatically generated by a dependency vulnerability scan.
Vulnerability: GHSA-5xrq-8626-4rwp
Package:
vitestEcosystem: npm
Affected versions:
>=4.0.0 <4.1.0Severity: critical
CVSS Score: 9.8
Description
When Vitest UI server is listening, arbitrary file can be read and executed
Advisory
GHSA-5xrq-8626-4rwp
Fix Recommendation
A fix is available. Run
npm audit fixto update affected dependencies, or manually updatevitestto the latest patched version.This issue was automatically generated by a dependency vulnerability scan.