3.0.5
3 years ago
2 days ago
Known vulnerabilities in the vitest package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
vitest is a Next generation testing framework powered by Vite Affected versions of this package are vulnerable to Missing Origin Validation in WebSockets through the WebSocket server setup, due to missing checks of the Origin header and authorization mechanism. An attacker can execute arbitrary code by injecting malicious code into a test file using the How to fix Missing Origin Validation in WebSockets? Upgrade | >=1.0.0 <1.6.1>=2.0.0 <2.1.9<3.0.5 |
vitest is a Next generation testing framework powered by Vite Affected versions of this package are vulnerable to Directory Traversal through the Note: This is only exploitable if the server is explicitly exposed to the network with How to fix Directory Traversal? Upgrade | >=2.0.4 <2.1.9>=3.0.0 <3.0.4 |