#VU127489 Path traversal in vitest - CVE-2025-24963
Published: February 4, 2025 / Updated: April 24, 2026
vitest
Vitest
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the __screenshot-error handler on the browser mode HTTP server when handling requests with a user-supplied file parameter. A remote attacker can send a specially crafted request to disclose sensitive information.
Only instances with browser.api.host enabled and exposed on the network are vulnerable.