securityonline.info 6/16/2026, 3:47:26 AM · external

Vitest RCE Vulnerability (CVSS 9.8): Public PoC Disclosed for Testing Tool With 57M Weekly Downloads (CVE-2026-53633)

Vitest RCE Vulnerability (CVSS 9.8): Public PoC Disclosed for Testing Tool With 57M Weekly Downloads (CVE-2026-53633)
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses a critical remote code execution (RCE) vulnerability in the Vitest testing framework, tracked as CVE-2026-53633, with a CVSS score of 9.8. The vulnerability arises from the Browser Mode's cdp() API, which allows attackers to bypass write and exec protections and overwrite configuration files. If exposed to the network, this can lead to unauthorized access and execution of malicious code. The flaw particularly affects projects using CDP-capable providers.

Developers are advised to upgrade to the latest versions (v4.1.8 for 4.x and v3.2.5 for 3.x) and to avoid exposing Browser Mode to untrusted networks until patched.

View Primary Source Via securityonline.info

Article by CyberSIXT