Skip to content

[GHSA-5xrq-8626-4rwp] Doesn't show all remediated versions #7884

@t1m0thyj

Description

@t1m0thyj

The advisory says that all versions <4.1.0 are vulnerable, but this range seems inaccurate.

Other reporting tools like snyk.io show that vitest@3 has the vulnerability fixed in v3.2.5 and v4.1.6:
Image

I believe the fix for thevitest vulnerability was backported to the V3 branch: vitest-dev/vitest#10456
So the patched versions should be >=3.2.5, >=4.1.6, >=5.0.0-beta.3

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions