Tag
critical
threat
Vitest Arbitrary File Read Vulnerability
2 rules 2 TTPsAn arbitrary file read vulnerability exists in Vitest when the UI server is listening, especially when exposed to the network, allowing an attacker to read arbitrary files outside the project directory and potentially execute arbitrary scripts.
vitest
arbitrary-file-read
code-execution
cve-2026-47429
2r
2t
critical
advisory
Vitest Browser Mode XSS via otelCarrier Parameter Leads to RCE
2 rules 2 TTPs 2 IOCsVitest browser mode is vulnerable to reflected cross-site scripting (XSS) due to the `otelCarrier` query parameter being inserted directly into an inline module script without sanitization, enabling an attacker to craft a browser-runner URL that executes arbitrary JavaScript in the Vitest server origin, potentially leading to remote code execution (RCE).
@vitest/browser
xss
rce
vitest
javascript
dependency-vulnerability
2r
2t
2i