CVE-2026-84373: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:register handler on Vite's unauthenticated HMR WebSocket without validating redirect targets against the file-serving allowlist. The implementation processes event.redirect without enforcing server.fs.allow and server.fs.deny through isFileLoadingAllowed. A remote client that can reach an exposed development server can submit an opaque URL scheme preserving .. segments, causing join(server.config.root, redirectUrl.pathname) to resolve outside the project root. The plugin's load hook then returns readFile(mock.redirect, 'utf-8') as module source, disclosing local files readable by the dev-server process. Vitest browser mode uses a token-authenticated RPC and is not remotely unauthenticated by default, although the same boundary check was missing on that path. This issue is fixed in versions 4.1.11 and 5.0.0-rc.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vitest/@vitest/mockerto a version that resolves this vulnerability.Fixed in 4.1.11 - Upgrade
Upgrade
vitest/@vitest/mockerto a version that resolves this vulnerability.Fixed in 5.0.0-rc.2
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote client that can reach an exposed Vitest development server can use the unauthenticated Vite HMR WebSocket handler. No authentication or user interaction is required on that path.
What access does an attacker gain?
The attacker can cause the server to read local files outside the project root when those files are readable by the development-server process. The disclosed file contents are returned as module source; the provided data does not indicate integrity or availability impact.
Are Vitest browser-mode deployments remotely exposed by default?
Vitest browser mode uses a token-authenticated RPC and is not remotely unauthenticated by default. The missing boundary check also existed on that path, but the described unauthenticated remote exposure concerns the Vite HMR WebSocket path.
What should be done if an update cannot be applied immediately?
Prevent remote clients from reaching the development server and its HMR WebSocket. This removes the network access required for the described attack.
How can I determine whether an instance is affected?
Check whether the deployment uses the public mockerPlugin or standalone interceptorPlugin export from packages/mocker/src/node/interceptorPlugin.ts and runs an affected release. The issue is fixed in versions 4.1.11 and 5.0.0-rc.2.