Vitest 是一个由 Vite 驱动的测试框架。在从 2.1.0 到 4.1.11 和 5.0.0-rc.2 版本中,位于 中的公开导出的 和独立的 ,在 Vite 的未认证 HMR WebSocket 上注册了 处理器,但未针对文件服务白名单对重定向目标进行校验。具体实现中,处理 时,没有通过 来强制执行 和 配置。能够访问已暴露的开发服务器的远程客户端可以提交一个包含 段的、不透明的 URL 协议,导致 解析到项目根目录之外。随后,该插件的 钩子会将 的结果作为模块源码返回,从而泄露开发服务器进程可读的本地文
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vitest-dev | vitest | >= 2.1.0, < 4.1.11 | - |
|
| @vitest | mocker | >= 2.1.0, < 4.1.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet