Skip to content

chore(deps): update dependency vitest to v3 [security] - #116

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-vitest-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-vitest-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 29, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
vitest (source) ^0.34.0 → ^3.2.6 age confidence
vitest (source) ^0.34.1 → ^3.0.0 age confidence

When Vitest UI server is listening, arbitrary file can be read and executed

CVE-2026-47429 / GHSA-5xrq-8626-4rwp

More information

Details

Summary

Arbitrary file can be read on Windows when Vitest UI server is listening, especially when exposed to the network.

Impact

Only users that match either of the following conditions are affected:

  • explicitly exposes the Vitest UI server to the network (using --api.host or api.host config option)
  • running the Vitest UI or Browser Mode on Windows
Details

The API handler for /__vitest_attachment__ uses the deprecated isFileServingAllowed incorrectly.
https://github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/ui/node/index.ts#L77
The function expects the passed value to use cleanUrl after the check before file system related operation.
Because of this, it is possible to bypass the check by \\?\\..\\. This is not possible on Linux as Linux errors if a directory named ? does not exist.

A similar problem exists in other places as well.

That said, this isFileServingAllowed check does not actually prevent the API to be abused. Since the API has rerun feature and file write feature, it's possible to run arbitrary script by writing a script as a test file using saveTestFile and running it using rerun. This means exposing the API / Vitest UI is equivalent to giving script execution access.
On the browser mode side, there're readFile / writeFile / saveSnapshotFile. So exposing the browser mode is equivalent to giving file read / write access.

PoC
  1. Run Vitest UI
  2. Get the API token by curl http://localhost:51204/__vitest__/
  3. Run curl "http://localhost:51204/__vitest_attachment__?path=C:\\path\\to\\project\\?\\..\\..\\secret.txt&contentType=text/plain&token=$TOKEN" (TOKEN is the API token)
  4. curl shows the content of secret.txt that is outside the project directory
Mitigations

Vitest now ships two configuration flags, allowWrite and allowExec, that gate the privileged operations exploited by this vulnerability. Both are disabled by default whenever the API server is bound to a non-localhost host, ensuring that exposing the server to the network no longer implicitly grants write or execute capabilities to remote clients.

When these flags are disabled, the UI also enters a read-only mode: in-browser code editing and test file execution are turned off, removing the attack surface that allowed remote code execution. Many Browser Mode features are also disabled, like attachments, artifacts or snapshots. See browser.api.

Users who require the full interactive UI on a networked host must explicitly opt in by setting allowWrite and/or allowExec to true.

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vitest-dev/vitest (vitest)

v3.2.6

Compare Source

v3.2.5

Compare Source

v3.2.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.2.3

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v3.2.2

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v3.2.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.2.0

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v3.1.4

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.2

Compare Source

   🐞 Bug Fixes
   🏎 Performance
    View changes on GitHub

v3.1.1

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.1.0

Compare Source

🚀 Features
🐞 Bug Fixes
🏎 Performance
View changes on GitHub

v3.0.9

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v3.0.8

Compare Source

   🐞 Bug Fixes

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 9bee0ee to 5e7b90b Compare August 30, 2026 02:39
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Aug 30, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 5e7b90b to cb0c59f Compare September 2, 2026 21:36
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from cb0c59f to 4ceae5d Compare September 3, 2026 03:53
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 4ceae5d to 2116355 Compare September 3, 2026 09:53
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch 2 times, most recently from 3ec82cc to dbc0c5b Compare September 4, 2026 02:47
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 4, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from dbc0c5b to 1632168 Compare September 7, 2026 15:49
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 7, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 1632168 to e782083 Compare September 7, 2026 21:07
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 7, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from e782083 to 44633cc Compare September 9, 2026 21:54
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 44633cc to a604b5b Compare September 10, 2026 03:47
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from a604b5b to 0d5b967 Compare September 10, 2026 16:44
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 0d5b967 to 7f16a80 Compare September 11, 2026 01:07
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 11, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 7f16a80 to b05baf5 Compare September 15, 2026 17:55
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 15, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from b05baf5 to fbb8242 Compare September 16, 2026 01:37
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 16, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from fbb8242 to 4914e25 Compare September 16, 2026 13:32
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 16, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 4914e25 to 1a905a3 Compare September 17, 2026 03:18
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 17, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 1a905a3 to d638c51 Compare September 17, 2026 22:23
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 17, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from d638c51 to 4347570 Compare September 18, 2026 02:53
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 4347570 to d2279db Compare September 18, 2026 15:48
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from d2279db to b3500f4 Compare September 19, 2026 00:35
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 19, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from b3500f4 to 859f18f Compare September 23, 2026 19:17
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest [security] Sep 23, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 859f18f to ba13a63 Compare September 24, 2026 04:57
@renovate renovate Bot changed the title chore(deps): update dependency vitest [security] chore(deps): update dependency vitest to v3 [security] Sep 24, 2026
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] chore(deps): update dependency vitest to v3 [security] - autoclosed Sep 25, 2026
@renovate renovate Bot closed this Sep 25, 2026
@renovate
renovate Bot deleted the renovate/npm-vitest-vulnerability branch September 25, 2026 04:56
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v3 [security] - autoclosed chore(deps): update dependency vitest to v3 [security] Sep 25, 2026
@renovate renovate Bot reopened this Sep 25, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch 2 times, most recently from ba13a63 to 6751c91 Compare September 25, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants