Skip to content

fix(deps): upgrade vitest to ^4.1.0 to fix CVE-2026-47429#28

Merged
davidkonigsberg merged 1 commit into
mainfrom
devin/1780395852-fix-vitest-cve
Jun 2, 2026
Merged

fix(deps): upgrade vitest to ^4.1.0 to fix CVE-2026-47429#28
davidkonigsberg merged 1 commit into
mainfrom
devin/1780395852-fix-vitest-cve

Conversation

@davidkonigsberg
Copy link
Copy Markdown
Contributor

Summary

Bumps vitest from ^4.0.18 to ^4.1.0 to resolve CVE-2026-47429 (CVSS 9.8 Critical) — arbitrary file read/execute when the Vitest UI server is listening on the network.

vitest is a devDependency only, so dist/ is unchanged.

Link to Devin session: https://app.devin.ai/sessions/57013560967e4b9e9e424a22a4dd5f08
Requested by: @davidkonigsberg

Co-Authored-By: David Konigsberg <davidakonigsberg@gmail.com>
@devin-ai-integration
Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@davidkonigsberg davidkonigsberg merged commit b0e6587 into main Jun 2, 2026
1 check passed
@davidkonigsberg davidkonigsberg deleted the devin/1780395852-fix-vitest-cve branch June 2, 2026 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants