Skip to content

fix: bump vitest to ^4.1.11 to clear GHSA-82fw-gwwq-j7x9 - #45

Merged
noctisreus merged 1 commit into
mainfrom
fix/vitest-4-security-bump
Sep 30, 2026
Merged

noctisreus merged 1 commit into
mainfrom
fix/vitest-4-security-bump

Conversation

@noctisreus

Copy link
Copy Markdown
Collaborator

Summary

Clears the last two advisories in the tree. vitest@3.2.6 / @vitest/mocker@3.2.6 are affected by a path traversal / arbitrary file read in @vitest/mocker (CVE-2026-84373, moderate, CVSS 5.9). Follows #43, which cleared the other 27.

A major bump is the only route. Upstream declared 2.1.x and 3.x unmaintained and shipped no backport — the 3.x line ends at 3.2.7, published 2026-07-06, before the fix landed in 4.1.11 on 2026-08-18. There is no 3.2.8.

The two Dependabot alerts were not duplicates: one was filed against package.json (the declared ^3.2.6 range) and one against pnpm-lock.yaml. A pnpm.overrides entry would have silenced only the lockfile one, which is why this changes the declared devDependency instead.

Supersedes #42, which proposed bumping @vitest/mocker to 5.0.0 on its own — that would leave it mismatched against vitest@3.2.6.

Why 4.1.11 and not 5.0.3

4.1.11 is the dedicated patch containing exactly this fix ("restrict redirect mocks to the fs allowlist") on the maintained V4 tag. 5.0.3 shipped 2026-09-30, is a double major, requires Node >=22.12 and makes vite peer-only — for no additional security benefit, since both fix the CVE identically. Stated plainly: 4.x will eventually go unmaintained the way 3.x just did, so moving to 5.x is a scheduled maintenance task, not a security one.

Exploitability here is effectively nil

This is alert hygiene, not an incident. The attack requires a reachable Vite dev server plus its unauthenticated HMR websocket to emit a vitest:interceptor:register event. pnpm test is vitest run, which stands up no server, and there is no vi.mock anywhere in the suite, so the mocker never engages at all. vitest is a devDependency and files: ["dist"], so nothing reaches consumers of the published package.

Changes

  • package.json — one line: devDependencies.vitest ^3.2.6 → ^4.1.11.
  • pnpm-lock.yaml — the vitest 3→4 subtree (net −82 lines; v4 has a slimmer dependency graph).

No config or test changes were needed. defineConfig from vitest/config plus test.include and test.environment are unchanged in v4, and the six suites import only describe/it/expect — no mocks, spies, snapshots, coverage, pools config, custom reporters or workspace — so none of v4's breaking changes intersect this usage.

Compatibility checked: vite stays 7.3.5 (satisfies v4's ^6||^7||^8 peer range), and engines.node ^20||^22||>=24 is satisfied by CI's lts/*. @types/node is deliberately left at ^18.19.0: it sits outside v4's optional peer range but emits no warning and all gates pass, so bumping it would add unrelated risk to a security PR.

Test plan

No source files changed — the node's runtime behavior is untouched.

vitest 3.2.6 and @vitest/mocker 3.2.6 are affected by a path traversal /
arbitrary file read in @vitest/mocker (CVE-2026-84373, moderate, CVSS 5.9).
A major bump is the only route: upstream declared 2.1.x and 3.x unmaintained
and shipped no backport. The 3.x line ends at 3.2.7, published 2026-07-06,
before the fix landed in 4.1.11 on 2026-08-18.

Two Dependabot alerts covered this, and they were not duplicates: one was
filed against package.json (the declared ^3.2.6 range) and one against
pnpm-lock.yaml. A pnpm override would have silenced only the lockfile one,
which is why this changes the declared devDependency instead.

Chose 4.1.11 over 5.0.3. 4.1.11 is the dedicated patch containing exactly
this fix ("restrict redirect mocks to the fs allowlist") on the maintained V4
tag. 5.0.3 shipped 2026-09-30, is a double major, requires Node >=22.12 and
makes vite peer-only, for no additional security benefit. Note that 4.x will
eventually go unmaintained the way 3.x did, so moving to 5.x is a scheduled
maintenance task rather than a security one.

Exploitability here is effectively nil and this is alert hygiene: the attack
requires a reachable Vite dev server plus its unauthenticated HMR websocket,
and `pnpm test` is `vitest run`, which starts no server. There is no vi.mock
anywhere in the suite, so the mocker never engages. vitest is a devDependency
and files is ["dist"], so nothing reaches consumers of the published package.

No config or test changes were needed. defineConfig from vitest/config plus
test.include and test.environment are unchanged in v4, and the six suites
import only describe/it/expect with no mocks, spies, snapshots, coverage,
pools config, custom reporters or workspace, so none of v4's breaking changes
intersect this usage. vite stays 7.3.5, satisfying the ^6||^7||^8 peer range.
Node ^20||^22||>=24 is satisfied by CI's lts/*.

pnpm audit is now fully clean. Build, lint and tests are green.
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@noctisreus
noctisreus merged commit 375d736 into main Sep 30, 2026
7 checks passed
@noctisreus
noctisreus deleted the fix/vitest-4-security-bump branch September 30, 2026 20:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant