CyberRota Analysis
AI-GeneratedThe Vitest UI/API server on Windows is vulnerable to a path traversal flaw that allows attackers to read files outside the project directory, as well as exploit exposed API features for arbitrary script execution. This critical vulnerability impacts users running versions prior to 3.2.5 and 4.1.0, and organizations utilizing Vitest for testing should prioritize immediate updates to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)