{"id":"CGA-vcc7-87g3-4cvw","modified":"2026-09-11T05:32:56.024307852Z","published":"2026-09-10T18:10:14Z","upstream":["CVE-2026-47429","GHSA-5xrq-8626-4rwp"],"references":[{"type":"WEB","url":"https://github.com/vitest-dev/vitest/releases/tag/v3.2.5"},{"type":"WEB","url":"https://github.com/vitest-dev/vitest/releases/tag/v4.1.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47429.json"},{"type":"ADVISORY","url":"https://github.com/vitest-dev/vitest/security/advisories/GHSA-5xrq-8626-4rwp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47429"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/commit/20e00ef7808de6d330c5e2fda530f686e08f1c8d"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/commit/af88b1f5d82844a4761ea9a977156c98e2b14ca8"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/pull/10445"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/pull/9350"}],"affected":[{"package":{"name":"commercial-gitlab-rails-ee-fips-19.1","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/commercial-gitlab-rails-ee-fips-19.1?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_type":"npm","component_location":"/srv/gitlab/yarn.lock","component_purl":"pkg:npm/vitest@4.0.8","latest_event_status":"pending_upstream_fix","latest_event_timestamp":"2026-09-10T18:10:24Z","component_name":"vitest","component_version":"4.0.8"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-vcc7-87g3-4cvw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}