CVE-2025-24964Patch(vitest.dev / vitest)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vitest.dev vitest systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. When `api` option is enabled (Vitest UI enables it), Vitest starts a WebSocket server. This WebSocket server did not check Origin header and did not have any authorization mechanism and was vulnerable to CSWSH attacks. This WebSocket server has `saveTestFile` API that can edit a test file and `rerun` API that can rerun the tests. An attacker can execute arbitrary code by injecting a code in a test file by the `saveTestFile` API and then running that file by calling the `rerun` API. This vulnerability can result in remote code execution for users that are using Vitest serve API. This issue has been patched in versions 1.6.1, 2.1.9 and 3.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1385

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vitest

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
vitest

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-19: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • DaoDial@_daodial
    Patch

    🔐 Critical dependency issue detected by our ScanMyBot agent in Conway Research automation repo. CVE-2025-24964 allows potential remote code execution when the Vitest API server is exposed (https://nvd.nist.gov/vuln/detail/CVE-2025-24964). Please upgrade to v2.1.9 or later. To scan your ai agent visit http://web.daodial.com

    Post summary

    The text announces CVE-2025-24964, a remote code execution flaw in the Vitest API server, and recommends upgrading to version 2.1.9 or newer.

    12240650
    101 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvitest.devvitest-node.js-

Explore more