Next generation testing framework powered by Vite
90%
Total Score
63
85
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-24964 vitest is vulnerable to Missing Origin Validation in WebSockets in versions 1.0.0 - 1.6.1, 2.0.0 - 2.1.9, 3.0.0 - 3.0.5 and 0.0.0 - 0.0.125. | 0.0.0 - 0.0.1251.0.0 - 1.6.12.0.0 - 2.1.9 +1 more | Critical |
| Dependency | Last Release | Score |
|---|---|---|
obug Version ^2.1.1 | — | — |
vite Version ^6.0.0 || ^7.0.0 || ^8.0.0 | — | — |
pathe Version ^2.0.3 | — | — |
std-env Version ^4.0.0-rc.1 | — | — |
tinyexec Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant