Critical severity9.6GHSA Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-47428
CVE-2026-47428
Description
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@vitest/browsernpm | >= 4.0.17, < 4.1.6 | 4.1.6 |
@vitest/browsernpm | >= 5.0.0-beta.0, < 5.0.0-beta.3 | 5.0.0-beta.3 |
Affected products
1- Range: >= 5.0.0-beta.0, < 5.0.0-beta.3
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-2h32-95rg-cpppghsaADVISORY
- github.com/vitest-dev/vitest/blob/cba2036a197ec8ed42c35a37db78ef07192202c7/packages/browser/src/client/public/esm-client-injector.jsghsaWEB
- github.com/vitest-dev/vitest/blob/cba2036a197ec8ed42c35a37db78ef07192202c7/packages/browser/src/node/serverOrchestrator.tsghsaWEB
- github.com/vitest-dev/vitest/security/advisories/GHSA-2h32-95rg-cpppnvdWEB
- github.com/vitest-dev/vitest/commit/18af98cee1830604d57f6a02bf28f8067cdffc06nvd
- github.com/vitest-dev/vitest/commit/3514f9fa135c90e1c35754fc4d27c9cf351faafanvd
- github.com/vitest-dev/vitest/pull/10283nvd
- github.com/vitest-dev/vitest/pull/10285nvd
- github.com/vitest-dev/vitest/releases/tag/v4.1.6nvd
- github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.3nvd
News mentions
0No linked articles in our index yet.