mocker is vulnerable to Path Traversal
59
Medium Risk
The mocker plugin registers redirect mocks without validating the redirect target against the dev server's filesystem allowlist. A client that can reach the mocker WebSocket can register a redirect whose target resolves outside the project root. This exposes arbitrary local files served through the development server, leading to file disclosure. The fix restricts redirect mock targets to the filesystem allowlist and disables unauthenticated raw WebSocket mock registration.
You are affected if you use a version in the vulnerable range and run the browser or dev server so its mocker WebSocket is reachable by untrusted or externally influenced clients.
mocker is vulnerable to Path Traversal in versions 2.1.0 - 4.1.10.
Upgrade the mocker and/or the @vitest/mocker library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant