Skip to content

fix: upgrade @vitest/browser to 4.1.10, 3.2.7, 5.0.0-beta.6 (GHSA-p63j-vcc4-9vmv) - #236

Open
anupamme wants to merge 1 commit into
chialab:mainfrom
anupamme:fix-repo-rna-ghsa-p63j-vcc4-9vmv-vitest-browser
Open

fix: upgrade @vitest/browser to 4.1.10, 3.2.7, 5.0.0-beta.6 (GHSA-p63j-vcc4-9vmv)#236
anupamme wants to merge 1 commit into
chialab:mainfrom
anupamme:fix-repo-rna-ghsa-p63j-vcc4-9vmv-vitest-browser

Conversation

@anupamme

@anupamme anupamme commented Aug 4, 2026

Copy link
Copy Markdown

Summary

Upgrade @vitest/browser from 4.1.7 to 4.1.10, 3.2.7, 5.0.0-beta.6 to fix GHSA-p63j-vcc4-9vmv.

Vulnerability

Field Value
ID GHSA-p63j-vcc4-9vmv
Severity CRITICAL
Scanner trivy
Rule GHSA-p63j-vcc4-9vmv
File yarn.lock (dependency: @vitest/browser)
Assessment Defensive hardening

Description: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate

Changes

  • package.json
  • yarn.lock

Behavior Preservation

The change is scoped to 2 files on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated dependency upgrade by OrbisAI Security
@changeset-bot

changeset-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: fada900

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant