Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Vitest.Dev Vitest
cpe:2.3:a:vitest.dev:vitest:*:*:*:*:*:node.js:*:*
|
— |
3.2.5
|
|
Vitest.Dev Vitest
cpe:2.3:a:vitest.dev:vitest:*:*:*:*:*:node.js:*:*
|
4.0.0
|
4.1.0
|