Critical severity9.8NVD Advisory· Published Jul 14, 2026· Updated Aug 6, 2026
CVE-2026-47429
CVE-2026-47429
Description
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
vitestnpm | >= 4.0.0, < 4.1.0 | 4.1.0 |
vitestnpm | < 3.2.6 | 3.2.6 |
Affected products
13- osv-coords11 versionspkg:apk/chainguard/gitlab-rails-ce-19.0pkg:apk/chainguard/gitlab-rails-ce-19.1pkg:apk/chainguard/gitlab-rails-ce-fips-19.0pkg:apk/chainguard/gitlab-rails-ce-fips-19.1pkg:apk/chainguard/gitlab-rails-ce-fips-19.2pkg:apk/chainguard/langfuse-2-workerpkg:apk/chainguard/langfuse-fips-2-workerpkg:apk/chainguard/vitess-23pkg:apk/wolfi/vitess-23pkg:apk/chainguard/gitlab-rails-ce-18.11pkg:apk/chainguard/gitlab-rails-ce-fips-18.11
< 19.0.3-r3+ 10 more
- (no CPE)range: < 19.0.3-r3
- (no CPE)range: < 19.1.2-r2
- (no CPE)range: < 19.0.3-r4
- (no CPE)range: < 19.1.1-r3
- (no CPE)range: < 19.2.1-r1
- (no CPE)range: < 2.95.12-r25
- (no CPE)range: < 2.95.12-r27
- (no CPE)range: < 23.0.4-r8
- (no CPE)range: < 23.0.4-r8
- (no CPE)range: < 18.11.6-r7
- (no CPE)range: < 18.11.6-r3
cpe:2.3:a:vitest.dev:vitest:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:vitest.dev:vitest:*:*:*:*:*:node.js:*:*range: <3.2.5
- (no CPE)range: <3.2.5, <4.1.0
Patches
Vulnerability mechanics
References
15- github.com/vitest-dev/vitest/commit/20e00ef7808de6d330c5e2fda530f686e08f1c8dnvdPatchWEB
- github.com/vitest-dev/vitest/commit/af88b1f5d82844a4761ea9a977156c98e2b14ca8nvdPatchWEB
- github.com/vitest-dev/vitest/pull/10445nvdExploitIssue TrackingPatchWEB
- github.com/vitest-dev/vitest/pull/9350nvdExploitIssue TrackingPatchWEB
- github.com/vitest-dev/vitest/security/advisories/GHSA-5xrq-8626-4rwpnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-5xrq-8626-4rwpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-47429ghsaADVISORY
- github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/browser/src/node/commands/fs.tsghsaWEB
- github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/browser/src/node/plugin.tsghsaWEB
- github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/browser/src/node/rpc.tsghsaWEB
- github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/ui/node/index.tsghsaWEB
- github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/vitest/src/api/setup.tsghsaWEB
- github.com/vitest-dev/vitest/blob/eb1abf08573032a532015b999ad3501c5e89e3bb/packages/vitest/src/api/setup.tsghsaWEB
- github.com/vitest-dev/vitest/releases/tag/v3.2.5nvdRelease NotesWEB
- github.com/vitest-dev/vitest/releases/tag/v4.1.0nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.