Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Vulnerability Description
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
暴露危险的方法或函数
Vulnerability Title
Vitest 权限许可和访问控制问题漏洞
Vulnerability Description
Vitest vitest是Vitest公司的一款快速的前端测试框架。 Vitest存在安全漏洞,该漏洞源于Browser Mode中的cdp() API未经allowWrite或allowExec检查直接转发Chrome DevTools Protocol方法,可能导致远程客户端使用CDP Page.setDownloadBehavior和Runtime.evaluate覆盖vite.config.ts并执行攻击者控制的Node.js代码。以下版本受到影响:3.0.0至3.2.5之前版本、4.0.0至4
CVSS Information
N/A
Vulnerability Type
N/A