Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-24963

Опубликовано: 04 фев. 2025
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
EPSS Низкий

Описание

Vitest is a testing framework powered by Vite. The __screenshot-error handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by browser.api.host: true, an attacker can send a request to that handler from remote to get the content of arbitrary files.This __screenshot-error handler on the browser mode HTTP server responds any file on the file system. This code was added by commit 2d62051. Users explicitly exposing the browser mode server to the network by browser.api.host: true may get any files exposed. This issue has been addressed in versions 2.1.9 and 3.0.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vitest.dev:vitest:*:*:*:*:*:node.js:*:*
Версия до 2.1.9 (исключая)
cpe:2.3:a:vitest.dev:vitest:*:*:*:*:*:node.js:*:*
Версия от 3.0.0 (включая) до 3.0.4 (исключая)

EPSS

Процентиль: 91%
0.06086
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.9
github
около 1 года назад

Vitest browser mode serves arbitrary files

EPSS

Процентиль: 91%
0.06086
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22