Healthy and well-supported; this release is suitable to depend on. Frequent releases, active work from 11 contributors, verified publishing, and strong repository security practices outweigh the limited workflow-risk caveat.
96%
Total Score
100
100
100
90
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-47429 vitest is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 4.0.0 - 4.1.0 and 0.0.0 - 3.2.6. | 0.0.0 - 3.2.64.0.0 - 4.1.0 | Critical |
CVE-2025-24964 vitest is vulnerable to Missing Origin Validation in WebSockets in versions 1.0.0 - 1.6.1, 2.0.0 - 2.1.9, 3.0.0 - 3.0.5 and 0.0.0 - 0.0.125. | 0.0.0 - 0.0.1251.0.0 - 1.6.12.0.0 - 2.1.9 +1 more | Critical |
| Dependency | Last Release | Score |
|---|---|---|
chai Version ^6.2.2 | — | — |
obug Version ^2.1.4 | — | — |
std-env Version ^4.2.0 | — | — |
tinyexec Version 1.3.0 | — | — |
picomatch Version ^4.0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.