CVE-2026-47429
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /_vitestattachment__, allowing \?\..\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/vitest-dev/vitest/releases/tag/v3.2.5, https://github.com/vitest-dev/vitest/releases/tag/v4.1.0, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47429.json, https://github.com/vitest-dev/vitest/security/advisories/GHSA-5xrq-8626-4rwp, https://nvd.nist.gov/vuln/detail/CVE-2026-47429, https://github.com/vitest-dev/vitest/commit/20e00ef7808de6d330c5e2fda530f686e08f1c8d, https://github.com/vitest-dev/vitest/commit/af88b1f5d82844a4761ea9a977156c98e2b14ca8, https://github.com/vitest-dev/vitest/pull/10445, https://github.com/vitest-dev/vitest/pull/9350