Executive brief
Vitest is a testing framework used by developers to verify their code. A vulnerability in its Browser Mode allows remote attackers to bypass security restrictions and execute malicious code on a developer's machine. This could lead to full system compromise, data theft, or unauthorized modification of project configuration files.
Technical details
A vulnerability exists in Vitest Browser Mode where the cdp() API forwarded raw Chrome DevTools Protocol (CDP) methods without being gated by allowWrite or allowExec security configurations. A remote client with access to browser API metadata could utilize CDP methods such as Page.setDownloadBehavior and Runtime.evaluate to overwrite the vite.config.ts file. This leads to the execution of attacker-controlled Node.js code. The issue is classified under CWE-749 (Exposed Dangerous Method or Function) and CWE-862 (Missing Authorization). Patches are available in versions 3.2.5, 4.1.8, and 5.0.0-beta.4.
Affected products
- vitest-dev vitest >= 3.0.0, < 3.2.5
- vitest-dev vitest >= 4.0.0, < 4.1.8
- vitest-dev vitest >= 5.0.0-beta.0, < 5.0.0-beta.4
Timeline
- 2026-07-14: advisory: NVD publication date
- 2026-05-28: patched: Fixes committed to repository
References
- https://github.com/vitest-dev/vitest/commit/385a1aefd4c2bfa5e7d58bf7c6834c929969f2c7
- https://github.com/vitest-dev/vitest/commit/63e3b2eee4d58da56786a6333f517b9b492528c7
- https://github.com/vitest-dev/vitest/commit/e4067b3b150005fd42cf75f994300119245806b9
- https://github.com/vitest-dev/vitest/pull/10444
- https://github.com/vitest-dev/vitest/pull/10450
- https://github.com/vitest-dev/vitest/pull/10456
- https://github.com/vitest-dev/vitest/releases/tag/v3.2.5