A AegiFlow
CRITICALCVSS 9.8EPSS 0.6%

CVE-2026-53633

CVE-2026-53633 updated by NVD

Published
2026-06-15
Modified
2026-08-13
EPSS percentile
45%
Sources
github-advisory, nvd

Summary

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@vitest/browser5.0.0-beta.4, 4.1.8, 3.2.5
npmvite-plus0.1.24

Remediation: Upgrade to 5.0.0-beta.4 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.