Critical severity9.8GHSA Advisory· Published Jul 14, 2026· Updated Jul 29, 2026
CVE-2026-53633
CVE-2026-53633
Description
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@vitest/browsernpm | >= 5.0.0-beta.0, < 5.0.0-beta.4 | 5.0.0-beta.4 |
@vitest/browsernpm | >= 4.0.0, < 4.1.8 | 4.1.8 |
@vitest/browsernpm | >= 3.0.0, < 3.2.5 | 3.2.5 |
vite-plusnpm | < 0.1.24 | 0.1.24 |
Affected products
3- ghsa-coords2 versions
>= 5.0.0-beta.0, < 5.0.0-beta.4+ 1 more
- (no CPE)range: >= 5.0.0-beta.0, < 5.0.0-beta.4
- (no CPE)range: < 0.1.24
- Range: <= 0.1.23
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-g8mr-85jm-7xhmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53633ghsaADVISORY
- github.com/vitest-dev/vitest/commit/385a1aefd4c2bfa5e7d58bf7c6834c929969f2c7nvdWEB
- github.com/vitest-dev/vitest/commit/63e3b2eee4d58da56786a6333f517b9b492528c7nvdWEB
- github.com/vitest-dev/vitest/commit/e4067b3b150005fd42cf75f994300119245806b9nvdWEB
- github.com/vitest-dev/vitest/pull/10444nvdWEB
- github.com/vitest-dev/vitest/pull/10450nvdWEB
- github.com/vitest-dev/vitest/pull/10456nvdWEB
- github.com/vitest-dev/vitest/releases/tag/v3.2.5nvdWEB
- github.com/vitest-dev/vitest/releases/tag/v4.1.8nvdWEB
- github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.4nvdWEB
- github.com/vitest-dev/vitest/security/advisories/GHSA-g8mr-85jm-7xhmnvdWEB
News mentions
0No linked articles in our index yet.