Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
Vulnerability Description
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Vitest 跨站脚本漏洞
Vulnerability Description
Vitest vitest是Vitest公司的一款快速的前端测试框架。 Vitest 4.0.17版本至4.1.6之前版本和5.0.0-beta.0版本至5.0.0-beta.3之前版本存在跨站脚本漏洞,该漏洞源于Browser Mode服务将otelCarrier查询参数直接插入到内联模块脚本中,允许经过构造的浏览器运行器URL在Vitest服务器源中执行任意JavaScript并恢复用于认证API调用的VITEST_API_TOKEN。
CVSS Information
N/A
Vulnerability Type
N/A