All CVEs
Vulnerability intelligence

CVE-2026-47429

vitest-dev vitest CWE-22

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.9%
Riskier than 58% of all CVEs · checked 2026-09-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry

1 article across 1 outlet · first covered Jun 5, 2026 · latest Jun 5, 2026

Coverage timeline

Related CVEs — vitest-dev