{"id":"CVE-2026-53633","aliases":["GHSA-g8mr-85jm-7xhm"],"url":"https://o3.security/vulnerability/CVE-2026-53633","summary":"Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE","details":"Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.","published":"2026-07-14T19:35:42.739Z","modified":"2026-08-12T03:51:47.036503763Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00896,"percentile":0.56833,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@vitest/browser","fixedVersion":"5.0.0-beta.4"},{"ecosystem":"npm","name":"@vitest/browser","fixedVersion":"4.1.8"},{"ecosystem":"npm","name":"@vitest/browser","fixedVersion":"3.2.5"},{"ecosystem":"npm","name":"vite-plus","fixedVersion":"0.1.24"}],"fix":{"url":"https://github.com/vitest-dev/vitest/commit/385a1aefd4c2bfa5e7d58bf7c6834c929969f2c7","label":"vitest-dev/vitest@385a1ae"},"references":[{"type":"WEB","url":"https://github.com/vitest-dev/vitest/releases/tag/v3.2.5"},{"type":"WEB","url":"https://github.com/vitest-dev/vitest/releases/tag/v4.1.8"},{"type":"WEB","url":"https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53633.json"},{"type":"ADVISORY","url":"https://github.com/vitest-dev/vitest/security/advisories/GHSA-g8mr-85jm-7xhm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53633"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/commit/385a1aefd4c2bfa5e7d58bf7c6834c929969f2c7"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/commit/63e3b2eee4d58da56786a6333f517b9b492528c7"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/commit/e4067b3b150005fd42cf75f994300119245806b9"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/pull/10444"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/pull/10450"},{"type":"FIX","url":"https://github.com/vitest-dev/vitest/pull/10456"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.036503763Z"}}