vitest@1.6.1 vulnerabilities

Next generation testing framework powered by Vite

  • latest version

    3.0.5

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the vitest package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Missing Origin Validation in WebSockets

    vitest is a Next generation testing framework powered by Vite

    Affected versions of this package are vulnerable to Missing Origin Validation in WebSockets through the WebSocket server setup, due to missing checks of the Origin header and authorization mechanism. An attacker can execute arbitrary code by injecting malicious code into a test file using the saveTestFile API and subsequently executing the file via the rerun API.

    How to fix Missing Origin Validation in WebSockets?

    Upgrade vitest to version 1.6.1, 2.1.9, 3.0.5 or higher.

    >=1.0.0 <1.6.1>=2.0.0 <2.1.9<3.0.5