Vulnerability intelligence
CVE-2026-47429
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.9%
Riskier than 58% of all CVEs · checked 2026-09-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jun 5, 2026 · latest Jun 5, 2026
Coverage timeline
-
Critical Vitest flaws expose dev setups to remote code executionsecurityonline.info · Jun 5, 2026