Skip to content

chore(deps): update dependency vitest to v3 [security] - #147

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-vitest-vulnerability
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-vitest-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jun 6, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
vitest (source) ^1.6.0 → ^3.2.6 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


When Vitest UI server is listening, arbitrary file can be read and executed

CVE-2026-47429 / GHSA-5xrq-8626-4rwp

More information

Details

Summary

Arbitrary file can be read on Windows when Vitest UI server is listening, especially when exposed to the network.

Impact

Only users that match either of the following conditions are affected:

  • explicitly exposes the Vitest UI server to the network (using --api.host or api.host config option)
  • running the Vitest UI or Browser Mode on Windows
Details

The API handler for /__vitest_attachment__ uses the deprecated isFileServingAllowed incorrectly.
https://github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/ui/node/index.ts#L77
The function expects the passed value to use cleanUrl after the check before file system related operation.
Because of this, it is possible to bypass the check by \\?\\..\\. This is not possible on Linux as Linux errors if a directory named ? does not exist.

A similar problem exists in other places as well.

That said, this isFileServingAllowed check does not actually prevent the API to be abused. Since the API has rerun feature and file write feature, it's possible to run arbitrary script by writing a script as a test file using saveTestFile and running it using rerun. This means exposing the API / Vitest UI is equivalent to giving script execution access.
On the browser mode side, there're readFile / writeFile / saveSnapshotFile. So exposing the browser mode is equivalent to giving file read / write access.

PoC
  1. Run Vitest UI
  2. Get the API token by curl http://localhost:51204/__vitest__/
  3. Run curl "http://localhost:51204/__vitest_attachment__?path=C:\\path\\to\\project\\?\\..\\..\\secret.txt&contentType=text/plain&token=$TOKEN" (TOKEN is the API token)
  4. curl shows the content of secret.txt that is outside the project directory
Mitigations

Vitest now ships two configuration flags, allowWrite and allowExec, that gate the privileged operations exploited by this vulnerability. Both are disabled by default whenever the API server is bound to a non-localhost host, ensuring that exposing the server to the network no longer implicitly grants write or execute capabilities to remote clients.

When these flags are disabled, the UI also enters a read-only mode: in-browser code editing and test file execution are turned off, removing the attack surface that allowed remote code execution. Many Browser Mode features are also disabled, like attachments, artifacts or snapshots. See browser.api.

Users who require the full interactive UI on a networked host must explicitly opt in by setting allowWrite and/or allowExec to true.

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vitest-dev/vitest (vitest)

v3.2.6

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.2.5

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v3.2.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.2.3

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v3.2.2

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v3.2.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.2.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v3.1.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.2

Compare Source

   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub

v3.1.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.0

Compare Source

🚀 Features
🐞 Bug Fixes
🏎 Performance
View changes on GitHub

v3.0.9

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.0.8

Compare Source

   🐞 Bug Fixes

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 6, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
saveto 213ae13 Oct 05 2026, 09:06 PM

@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from fff4c09 to 01e7dfa Compare June 6, 2026 09:03
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v4 [security] - autoclosed Jun 8, 2026
@renovate renovate Bot closed this Jun 8, 2026
@renovate
renovate Bot deleted the renovate/npm-vitest-vulnerability branch June 8, 2026 17:07
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] - autoclosed chore(deps): update dependency vitest to v3 [security] Jun 8, 2026
@renovate renovate Bot reopened this Jun 8, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch 3 times, most recently from 223c1e5 to f9f2217 Compare June 11, 2026 16:11
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Jun 11, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from f9f2217 to 3f811a5 Compare June 12, 2026 00:39
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Jun 12, 2026
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Jun 18, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch 2 times, most recently from 62dee22 to f13fafb Compare June 19, 2026 00:37
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Jun 19, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from f13fafb to 66fd8e9 Compare July 12, 2026 10:50
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Jul 12, 2026
@socket-security

socket-security Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 66fd8e9 to 9f8a1e6 Compare July 12, 2026 16:45
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Jul 12, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 9f8a1e6 to 7b238be Compare July 17, 2026 01:24
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Jul 17, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 7b238be to 0593c11 Compare July 17, 2026 08:32
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Jul 17, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 0593c11 to d95a257 Compare July 21, 2026 00:54
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Jul 21, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from d95a257 to 1f6ff07 Compare July 21, 2026 06:15
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Jul 21, 2026
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Aug 12, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 2266d04 to dd44678 Compare August 14, 2026 19:38
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Aug 14, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from dd44678 to 0e15bf4 Compare August 14, 2026 23:59
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Aug 14, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 0e15bf4 to 4a8e4c0 Compare August 21, 2026 13:39
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Aug 21, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 4a8e4c0 to 5e57c84 Compare August 21, 2026 19:49
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Aug 21, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 5e57c84 to 069e5b6 Compare August 26, 2026 17:10
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Aug 26, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 069e5b6 to 788364e Compare August 27, 2026 01:05
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Aug 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 788364e to 5f7c869 Compare September 2, 2026 19:43
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v4 [security] Sep 2, 2026
@socket-security

socket-security Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​vitest@​3.2.798997899100

View full report

@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 5f7c869 to c52f73a Compare September 3, 2026 01:52
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to v3 [security] Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from c52f73a to 93163b8 Compare September 3, 2026 14:00
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v5 [security] Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 93163b8 to 01516e4 Compare September 4, 2026 06:22
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v5 [security] chore(deps): update dependency vitest to v3 [security] Sep 4, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 01516e4 to 46297d9 Compare September 7, 2026 18:14
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v5 [security] Sep 7, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 46297d9 to 161151d Compare September 8, 2026 01:05
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v5 [security] chore(deps): update dependency vitest to v3 [security] Sep 8, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 161151d to 46cd0b3 Compare September 9, 2026 21:53
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v5 [security] Sep 9, 2026
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 19e65031-e986-4066-8287-c3ed9982b300

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants