Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47428

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /vitest_test/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3.

A flaw was found in Vitest, a testing framework. In Vitest Browser Mode, a remote attacker could craft a specific browser-runner URL that, when visited, would allow the execution of arbitrary JavaScript code within the Vitest server. This vulnerability could also lead to the recovery of the VITEST_API_TOKEN, potentially enabling unauthorized authenticated API calls and further compromise of the system.

Отчет

Red Hat has assessed this flaw against its shipping products. The vulnerability requires @vitest/browser (Vitest's opt-in Browser Mode) to be installed and actively enabled; it does not affect the core vitest test runner used without Browser Mode. None of Red Hat's shipping products install or execute @vitest/browser, and none configure or enable Browser Mode. Where Vitest is present, it is used strictly as a build/test-time devDependency (core vitest and its non-browser submodules such as expect, runner, snapshot, spy, and utils), not as a shipped runtime component, and several affected streams already ship patched versions (>=4.1.6) or versions below the vulnerable range. Accordingly, while the CVSS score reflects a genuinely severe flaw in Vitest Browser Mode upstream, Red Hat's shipping products are not reachable via this vulnerability.

Меры по смягчению последствий

No mitigation is required for Red Hat shipping products, as the vulnerable @vitest/browser package and Browser Mode feature are not present or enabled in any Red Hat product. Development teams using Vitest as a build/test-time dependency should avoid introducing @vitest/browser or enabling Browser Mode in CI/local environments, and should upgrade to Vitest >=4.1.6 (or >=5.0.0-beta.3 on the 5.x beta line) where Vitest is used, as a matter of general hygiene.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7vitestNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/gateway-rhel9Not affected
Red Hat Build of KeycloakvitestNot affected
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected
Red Hat JBoss Enterprise Application Platform 8vitestNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-ui-rhel9Not affected
Red Hat Hardened Imagesprometheus3-13-main-3.13.1-0.1.hum1FixedRHSA-2026:3905813.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2500578vitest: Vitest: Arbitrary code execution via crafted browser-runner URL

EPSS

Процентиль: 31%
0.00388
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
nvd
23 дня назад

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3.

CVSS3: 9.6
github
2 месяца назад

Vitest browser mode serves unsanitized otelCarrier query parameter as inline script

EPSS

Процентиль: 31%
0.00388
Низкий

8.3 High

CVSS3