Repository navigation
fix: bump vitest to ^4.1.11 to clear GHSA-82fw-gwwq-j7x9 - #45
Merged
Merged
Conversation
vitest 3.2.6 and @vitest/mocker 3.2.6 are affected by a path traversal / arbitrary file read in @vitest/mocker (CVE-2026-84373, moderate, CVSS 5.9). A major bump is the only route: upstream declared 2.1.x and 3.x unmaintained and shipped no backport. The 3.x line ends at 3.2.7, published 2026-07-06, before the fix landed in 4.1.11 on 2026-08-18. Two Dependabot alerts covered this, and they were not duplicates: one was filed against package.json (the declared ^3.2.6 range) and one against pnpm-lock.yaml. A pnpm override would have silenced only the lockfile one, which is why this changes the declared devDependency instead. Chose 4.1.11 over 5.0.3. 4.1.11 is the dedicated patch containing exactly this fix ("restrict redirect mocks to the fs allowlist") on the maintained V4 tag. 5.0.3 shipped 2026-09-30, is a double major, requires Node >=22.12 and makes vite peer-only, for no additional security benefit. Note that 4.x will eventually go unmaintained the way 3.x did, so moving to 5.x is a scheduled maintenance task rather than a security one. Exploitability here is effectively nil and this is alert hygiene: the attack requires a reachable Vite dev server plus its unauthenticated HMR websocket, and `pnpm test` is `vitest run`, which starts no server. There is no vi.mock anywhere in the suite, so the mocker never engages. vitest is a devDependency and files is ["dist"], so nothing reaches consumers of the published package. No config or test changes were needed. defineConfig from vitest/config plus test.include and test.environment are unchanged in v4, and the six suites import only describe/it/expect with no mocks, spies, snapshots, coverage, pools config, custom reporters or workspace, so none of v4's breaking changes intersect this usage. vite stays 7.3.5, satisfying the ^6||^7||^8 peer range. Node ^20||^22||>=24 is satisfied by CI's lts/*. pnpm audit is now fully clean. Build, lint and tests are green.
2 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Clears the last two advisories in the tree.
vitest@3.2.6/@vitest/mocker@3.2.6are affected by a path traversal / arbitrary file read in@vitest/mocker(CVE-2026-84373, moderate, CVSS 5.9). Follows #43, which cleared the other 27.A major bump is the only route. Upstream declared 2.1.x and 3.x unmaintained and shipped no backport — the 3.x line ends at
3.2.7, published 2026-07-06, before the fix landed in4.1.11on 2026-08-18. There is no3.2.8.The two Dependabot alerts were not duplicates: one was filed against
package.json(the declared^3.2.6range) and one againstpnpm-lock.yaml. Apnpm.overridesentry would have silenced only the lockfile one, which is why this changes the declared devDependency instead.Supersedes #42, which proposed bumping
@vitest/mockerto 5.0.0 on its own — that would leave it mismatched againstvitest@3.2.6.Why 4.1.11 and not 5.0.3
4.1.11is the dedicated patch containing exactly this fix ("restrict redirect mocks to the fs allowlist") on the maintainedV4tag.5.0.3shipped 2026-09-30, is a double major, requires Node>=22.12and makesvitepeer-only — for no additional security benefit, since both fix the CVE identically. Stated plainly: 4.x will eventually go unmaintained the way 3.x just did, so moving to 5.x is a scheduled maintenance task, not a security one.Exploitability here is effectively nil
This is alert hygiene, not an incident. The attack requires a reachable Vite dev server plus its unauthenticated HMR websocket to emit a
vitest:interceptor:registerevent.pnpm testisvitest run, which stands up no server, and there is novi.mockanywhere in the suite, so the mocker never engages at all.vitestis a devDependency andfiles: ["dist"], so nothing reaches consumers of the published package.Changes
package.json— one line:devDependencies.vitest^3.2.6→^4.1.11.pnpm-lock.yaml— the vitest 3→4 subtree (net −82 lines; v4 has a slimmer dependency graph).No config or test changes were needed.
defineConfigfromvitest/configplustest.includeandtest.environmentare unchanged in v4, and the six suites import onlydescribe/it/expect— no mocks, spies, snapshots, coverage, pools config, custom reporters orworkspace— so none of v4's breaking changes intersect this usage.Compatibility checked:
vitestays 7.3.5 (satisfies v4's^6||^7||^8peer range), andengines.node ^20||^22||>=24is satisfied by CI'slts/*.@types/nodeis deliberately left at^18.19.0: it sits outside v4's optional peer range but emits no warning and all gates pass, so bumping it would add unrelated risk to a security PR.Test plan
pnpm audit→ No known vulnerabilities found (was 29 before fix: raise eight stale pnpm override floors to clear 27 advisories #43, 2 after)pnpm test→ 6 files, 16 tests passed on vitest 4.1.11pnpm build→ exit 0pnpm lint→ exit 0 (strict vian8n.strict: true)vitest.config.mtsand all test files unchangedNo source files changed — the node's runtime behavior is untouched.