VYPR
Critical severity9.4NVD Advisory· Published Aug 13, 2026· Updated Sep 9, 2026

CVE-2026-73653

CVE-2026-73653

Description

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@vitest/browsernpm
>= 4.0.0, < 4.1.104.1.10
@vitest/browsernpm
< 3.2.73.2.7
@vitest/browsernpm
>= 5.0.0-beta.1, < 5.0.0-beta.65.0.0-beta.6

Affected products

2

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.