SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-47429

CRITICAL · CVSS 9.8 EPSS 0.92% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The Vitest UI/API server on Windows is vulnerable to a path traversal flaw that allows attackers to read files outside the project directory, as well as exploit exposed API features for arbitrary script execution. This critical vulnerability impacts users running versions prior to 3.2.5 and 4.1.0, and organizations utilizing Vitest for testing should prioritize immediate updates to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47429
Severity
CRITICAL
CVSS
9.8
EPSS
0.92%
Windows

Original NVD Description

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)