Browser mode serves arbitrary files in vitest
Description
Vitest is a testing framework powered by Vite. The __screenshot-error handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by browser.api.host: true, an attacker can send a request to that handler from remote to get the content of arbitrary files.This __screenshot-error handler on the browser mode HTTP server responds any file on the file system. This code was added by commit 2d62051. Users explicitly exposing the browser mode server to the network by browser.api.host: true may get any files exposed. This issue has been addressed in versions 2.1.9 and 3.0.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@vitest/browsernpm | >= 2.0.4, < 2.1.9 | 2.1.9 |
@vitest/browsernpm | >= 3.0.0, < 3.0.4 | 3.0.4 |
Affected products
2- vitest-dev/vitestv5Range: >= 2.0.4, < 2.1.9
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
7- github.com/advisories/GHSA-8gvc-j273-4wm5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-24963ghsaADVISORY
- github.com/vitest-dev/vitest/blob/f17918a79969d27a415f70431e08a9445b051e45/packages/browser/src/node/plugin.tsghsax_refsource_MISCWEB
- github.com/vitest-dev/vitest/commit/2d62051f13b4b0939b2f7e94e88006d830dc4d1fghsax_refsource_MISCWEB
- github.com/vitest-dev/vitest/commit/ed9aeba212df04b83ed01810780663ff2cdd0adfghsaWEB
- github.com/vitest-dev/vitest/security/advisories/GHSA-8gvc-j273-4wm5ghsax_refsource_CONFIRMWEB
- vitest.dev/guide/browser/config.htmlghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.