-
Notifications
You must be signed in to change notification settings - Fork 2.4k
chore(deps): update dependency vitest to v2.1.9 [security] #1274
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
+538
−267
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Codecov Report
✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 8.85%. Comparing base (d95f040
) to head (7e32385
).
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.
Additional details and impacted files
@@ Coverage Diff @@ ## master #1274 +/- ## ====================================== Coverage 8.85% 8.85% ====================================== Files 57 57 Lines 1897 1897 Branches 24 24 ====================================== Hits 168 168 Misses 1729 1729
☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.
🚀 New features to boost your workflow:
- ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
- 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.
size-limit report 📦
|
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
February 9, 2025 13:32
e30ff5d
to
b528605
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
March 3, 2025 15:30
b528605
to
b6a4db6
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
2 times, most recently
from
March 17, 2025 18:06
da27b9d
to
29ac93a
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
April 1, 2025 12:10
29ac93a
to
f981d5a
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
April 8, 2025 12:20
f981d5a
to
cee9de6
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
April 24, 2025 10:35
cee9de6
to
88e94c8
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
May 19, 2025 17:55
88e94c8
to
8bb99d5
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
2 times, most recently
from
June 4, 2025 07:05
159e8f4
to
067d355
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
June 22, 2025 13:50
067d355
to
e2e9e08
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
July 2, 2025 22:32
e2e9e08
to
5cfaf3f
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
2 times, most recently
from
August 13, 2025 16:50
d29a778
to
7bac130
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
August 19, 2025 16:16
7bac130
to
87b4b66
Compare
@renovate
renovate
bot
force-pushed
the
renovate/npm-vitest-vulnerability
branch
from
August 31, 2025 09:57
87b4b66
to
7e32385
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.
This PR contains the following updates:
2.1.8
->2.1.9
GitHub Vulnerability Alerts
CVE-2025-24964
Summary
Arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks.
Details
When
api
option is enabled (Vitest UI enables it), Vitest starts a WebSocket server. This WebSocket server did not check Origin header and did not have any authorization mechanism and was vulnerable to CSWSH attacks.https://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L32-L46
This WebSocket server has
saveTestFile
API that can edit a test file andrerun
API that can rerun the tests. An attacker can execute arbitrary code by injecting a code in a test file by thesaveTestFile
API and then running that file by calling thererun
API.https://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026a55ce6a8cb35114/packages/vitest/src/api/setup.ts#L66-L76
PoC
calc
executable inPATH
env var (you'll likely have it if you are running on Windows), that application will be executed.Impact
This vulnerability can result in remote code execution for users that are using Vitest serve API.
Release Notes
vitest-dev/vitest (vitest)
v2.1.9
Compare Source
This release includes security patches for:
🐞 Bug Fixes
/__screenshot-error
- by @hi-ogawa in https://github.com/vitest-dev/vitest/pull/7343View changes on GitHub
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.