CVE-2026-53633
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.90%
- CWE
- CWE-749, CWE-862
- Published
- 2026-07-14
- Last modified
- 2026-07-29
Affected products
- vitest-dev vitest
- vitest-dev vitest
- vitest-dev vitest
Weakness type
Related vulnerabilities
- CVE-2026-20293 — Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
- CVE-2026-86711 — electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge
- CVE-2026-75810 — Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief...
- CVE-2026-18263 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2026-18262 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2026-13121 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2026-52877 — Streambert : Insecure Protocol Execution in open-external IPC Handler
- CVE-2026-66781 — Submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication