Executive brief
Vitest is a JavaScript testing framework with a browser mode that provides local HTTP server capabilities for running tests in browsers. An attacker can read arbitrary files from the server's filesystem by exploiting an unprotected HTTP handler, if the server is exposed to the network via the browser.api.host configuration option.
Technical details
The vulnerability is a path traversal / arbitrary file read flaw in the __screenshot-error HTTP handler of Vitest's browser mode. The handler accepts a 'file' query parameter and reads any file on the filesystem without validation or sanitization, returning its contents to the attacker. The attack requires network access to the Vitest browser server, which is only exposed remotely if browser.api.host is explicitly set to true. The vulnerability was introduced in version 2.0.4 and fixed in versions 2.1.9 and 3.0.4. No authentication or user interaction is required to exploit this vulnerability from a remote network attacker.
Affected products
- Vitest Vitest >=2.0.4, <2.1.9; >=3.0.0, <3.0.4
- Vitest @vitest/browser >=2.0.4, <2.1.9; >=3.0.0, <3.0.4
Timeline
- 2025-02-04: disclosed: Vulnerability disclosed via GHSA-8gvc-j273-4wm5
- 2025-02-04: patched: Fixed in Vitest 2.1.9 and 3.0.4