Catalog / Vitest

Vitest security advisories

All 7 advisories Vitest has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
76 carry a CVE
critical
5
medium
2
Fix in the archive
7of 7 matched to a release
Oldest
4 Feb 20251.6 years ago

Every advisory here is matched to the release in the archive that carries its fix. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-53633critical

Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

GHSA-g8mr-85jm-7xhmFixed in 4.1.8
CVE-2026-47429critical

Arbitrary file can be read and executed when Vitest UI server is listening

GHSA-5xrq-8626-4rwpFixed in 3.2.5
CVE-2026-47428critical

Vitest browser mode serves unsanitized otelCarrier query parameter as inline script

GHSA-2h32-95rg-cpppFixed in 4.1.6
CVE-2025-24964critical

Remote Code Execution when accessing a malicious website while Vitest API server is listening

GHSA-9crc-q9x8-hgqqFixed in 3.0.5