Описание
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /vitest_test/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3.
A flaw was found in Vitest, a testing framework. In Vitest Browser Mode, a remote attacker could craft a specific browser-runner URL that, when visited, would allow the execution of arbitrary JavaScript code within the Vitest server. This vulnerability could also lead to the recovery of the VITEST_API_TOKEN, potentially enabling unauthorized authenticated API calls and further compromise of the system.
Отчет
Red Hat has assessed this flaw against its shipping products. The vulnerability requires @vitest/browser (Vitest's opt-in Browser Mode) to be installed and actively enabled; it does not affect the core vitest test runner used without Browser Mode. None of Red Hat's shipping products install or execute @vitest/browser, and none configure or enable Browser Mode. Where Vitest is present, it is used strictly as a build/test-time devDependency (core vitest and its non-browser submodules such as expect, runner, snapshot, spy, and utils), not as a shipped runtime component, and several affected streams already ship patched versions (>=4.1.6) or versions below the vulnerable range. Accordingly, while the CVSS score reflects a genuinely severe flaw in Vitest Browser Mode upstream, Red Hat's shipping products are not reachable via this vulnerability.
Меры по смягчению последствий
No mitigation is required for Red Hat shipping products, as the vulnerable @vitest/browser package and Browser Mode feature are not present or enabled in any Red Hat product. Development teams using Vitest as a build/test-time dependency should avoid introducing @vitest/browser or enabling Browser Mode in CI/local environments, and should upgrade to Vitest >=4.1.6 (or >=5.0.0-beta.3 on the 5.x beta line) where Vitest is used, as a matter of general hygiene.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | vitest | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/gateway-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/gateway-rhel9 | Not affected | ||
| Red Hat Build of Keycloak | vitest | Not affected | ||
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | vitest | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-agent-installer-ui-rhel9 | Not affected | ||
| Red Hat Hardened Images | prometheus3-13-main-3.13.1-0.1.hum1 | Fixed | RHSA-2026:39058 | 13.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.3 High
CVSS3
Связанные уязвимости
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3.
Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
EPSS
8.3 High
CVSS3