CVE-2026-73653
Description
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@vitest/browsernpm | >= 4.0.0, < 4.1.10 | 4.1.10 |
@vitest/browsernpm | < 3.2.7 | 3.2.7 |
@vitest/browsernpm | >= 5.0.0-beta.1, < 5.0.0-beta.6 | 5.0.0-beta.6 |
Affected products
2- Range: <3.2.7, <4.1.10, <5.0.0-beta.6
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-p63j-vcc4-9vmvghsaADVISORY
- github.com/vitest-dev/vitest/commit/33f96a145ef09ca6a43b4e555eb273e64a87be23nvdWEB
- github.com/vitest-dev/vitest/commit/5c18dd267ff7f47f24cab2f615a16b37d90feb7fnvdWEB
- github.com/vitest-dev/vitest/commit/b795e36b34969bec50b47a9f29d26f799a6a04fbnvdWEB
- github.com/vitest-dev/vitest/pull/10674nvdWEB
- github.com/vitest-dev/vitest/pull/10679nvdWEB
- github.com/vitest-dev/vitest/pull/10680nvdWEB
- github.com/vitest-dev/vitest/releases/tag/v3.2.7nvdWEB
- github.com/vitest-dev/vitest/releases/tag/v4.1.10nvdWEB
- github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.6nvdWEB
- github.com/vitest-dev/vitest/security/advisories/GHSA-p63j-vcc4-9vmvnvdWEB
News mentions
0No linked articles in our index yet.