Junglewise Threat Intelligence

CVE-2026-53633: Vitest remote code execution in Browser Mode cdp API

CVE-2026-53633 · Severity: critical · CVSS 9.8 · Published 2026-07-14

Technologies: Vitest-Dev Vitest, vite-plus (npm). Vendors: npm.

Executive brief

Vitest is a testing framework used by developers to verify their code. A vulnerability in its Browser Mode allows remote attackers to bypass security restrictions and execute malicious code on a developer's machine. This could lead to full system compromise, data theft, or unauthorized modification of project configuration files.

Technical details

A vulnerability exists in Vitest Browser Mode where the cdp() API forwarded raw Chrome DevTools Protocol (CDP) methods without being gated by allowWrite or allowExec security configurations. A remote client with access to browser API metadata could utilize CDP methods such as Page.setDownloadBehavior and Runtime.evaluate to overwrite the vite.config.ts file. This leads to the execution of attacker-controlled Node.js code. The issue is classified under CWE-749 (Exposed Dangerous Method or Function) and CWE-862 (Missing Authorization). Patches are available in versions 3.2.5, 4.1.8, and 5.0.0-beta.4.

Affected products

  • vitest-dev vitest >= 3.0.0, < 3.2.5
  • vitest-dev vitest >= 4.0.0, < 4.1.8
  • vitest-dev vitest >= 5.0.0-beta.0, < 5.0.0-beta.4

Timeline

  • 2026-07-14: advisory: NVD publication date
  • 2026-05-28: patched: Fixes committed to repository

References

Related threats