Executive brief
Vitest is a JavaScript test runner that includes Browser Mode for running tests in actual browsers. Several built-in commands in Browser Mode can read, write, or delete arbitrary files on the server's filesystem by bypassing the allowWrite permission check. An attacker who can reach the Browser Mode API (e.g., if the test server is exposed to the network) can read sensitive files, overwrite application code, or delete critical data, even when file access restrictions are intended to be disabled.
Technical details
Vitest Browser Mode exposes Node.js-side provider commands (upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, annotateTraces) that perform file operations without enforcing the allowWrite permission gate or confining paths to the project directory. The vulnerability is a missing authorization check (CWE-862) combined with path traversal (CWE-22), allowing arbitrary file read/write/delete via client-supplied paths and traversal sequences. Attack requires network access to the Browser Mode API; no authentication or user interaction is required. The fix adds allowWrite checks and path confinement to the project root for all file-touching commands. Patches are available in v3.2.7, v4.1.10, and v5.0.0-beta.6.
Affected products
- Vitest Browser <3.2.7, >=4.0.0 <4.1.10, >=5.0.0-beta.1 <5.0.0-beta.6
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched: Fixed in v3.2.7, v4.1.10, v5.0.0-beta.6