@vitest/browser 5.0.0 appears to be a healthy, actively maintained package backed by the vitest-dev organization. It has a long release history with 236 releases, 61 releases in the last 12 months, current repository activity, broad recent contributor participation, type declarations, licensing, build provenance, security tooling, and read-only workflow permissions. The artifact omits tests and a changelog, but repository tests and GitHub Releases provide meaningful compensation; the only notable caution is the presence of two pull_request_target workflows, although no untrusted checkouts or script-injection findings were observed.
95%
Total Score
100
100
100
90
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-73653 @vitest/browser is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 4.0.0 - 4.1.10, 0.0.0 - 3.2.7 and 5.0.0-beta.1 - 5.0.0-beta.6. | 0.0.0 - 3.2.74.0.0 - 4.1.105.0.0-beta.1 - 5.0.0-beta.6 | Critical |
CVE-2026-53633 @vitest/browser is vulnerable to Exposed Dangerous Method or Function in versions 5.0.0-beta.0 - 5.0.0-beta.3, 4.0.0 - 4.1.7 and 3.0.0 - 3.2.4. | 3.0.0 - 3.2.44.0.0 - 4.1.75.0.0-beta.0 - 5.0.0-beta.3 | Critical |
CVE-2026-47428 @vitest/browser is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.17 - 4.1.6 and 5.0.0-beta.0 - 5.0.0-beta.3. | 4.0.17 - 4.1.65.0.0-beta.0 - 5.0.0-beta.3 | Critical |
CVE-2025-24963 @vitest/browser is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 2.0.4 - 2.1.9 and 3.0.0 - 3.0.4. | 2.0.4 - 2.1.93.0.0 - 3.0.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ws Version ^8.21.3 | — | — |
sirv Version ^3.0.2 | — | — |
pngjs Version ^7.0.0 | — | — |
@vitest/ui Version 5.0.0 | — | — |
tinyrainbow Version ^3.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.