Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.
CVE-2026-53633
This critical-severity CVE scores 9.8 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.6%, top 56% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(medium)
- EG Risk
- 75(Attend)EG Risk 75/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation40% × 40%Automatability100% × 15%Action: Remediate soon — notable exploitation risk. - EPSS
- 44.4%
- KEV
- Not listed
Published
June 15, 2026
Last Modified
July 16, 2026
Advisory Details (10)
Auto-updated Jul 16, 2026Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE · Advisory · vitest-dev/vitest · GitHub
https://github.com/vitest-dev/vitest/security/advisories/GHSA-g8mr-85jm-7xhmv5.0.0-beta.4
Patch available: vitest-dev/vitest v5.0.0-beta.4 (pre-release)
https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.4v4.1.8
Patch available: vitest-dev/vitest v4.1.8
https://github.com/vitest-dev/vitest/releases/tag/v4.1.8v3.2.5
Patch available: vitest-dev/vitest v3.2.5
https://github.com/vitest-dev/vitest/releases/tag/v3.2.5fix(browser): disable client `cdp` API when `allowWrite/allowExec: false` [backport to v3]
Patch available: vitest-dev/vitest v3.2.5 (PR #10456 merged 2026-05-28)
https://github.com/vitest-dev/vitest/pull/10456fix(browser): disable client `cdp` API when `allowWrite/allowExec: false` [backport to v4]
Patch available: vitest-dev/vitest v4.1.8 (PR #10450 merged 2026-05-28)
https://github.com/vitest-dev/vitest/pull/10450fix(browser): disable client `cdp` API when `allowWrite/allowExec: false`
Patch available: vitest-dev/vitest v5.0.0-beta.4 (PR #10444 merged 2026-05-28)
https://github.com/vitest-dev/vitest/pull/10444commit e4067b3b1500 (vitest-dev/vitest)
Patch available: vitest-dev/vitest v4.1.8 (contains commit e4067b3b1500)
https://github.com/vitest-dev/vitest/commit/e4067b3b150005fd42cf75f994300119245806b9commit 63e3b2eee4d5 (vitest-dev/vitest)
Patch available: vitest-dev/vitest v5.0.0-beta.4 (contains commit 63e3b2eee4d5)
https://github.com/vitest-dev/vitest/commit/63e3b2eee4d58da56786a6333f517b9b492528c7commit 385a1aefd4c2 (vitest-dev/vitest)
Patch available: vitest-dev/vitest v3.2.5 (contains commit 385a1aefd4c2)
https://github.com/vitest-dev/vitest/commit/385a1aefd4c2bfa5e7d58bf7c6834c929969f2c7Vendor Advisories for CVE-2026-53633(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Affected Packages
(2 across 1 ecosystem)
npm(2)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| vite-plus | — | 0.1.24 | — |
| @vitest/browser | — | 3.2.5 | — |
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 9× in last 7d / 11× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-23 03:19 UTCEG score recompute
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 02:29 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 17:03 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-06-15 20:11 UTCEG score recompute
Related CVEs(same CWE)
Same CWE
10 shownCWE-862 · CWE-749
Frequently asked(5)
What is CVE-2026-53633?
When was CVE-2026-53633 disclosed?
Is CVE-2026-53633 actively exploited?
What is the CVSS score of CVE-2026-53633?
How do I remediate CVE-2026-53633?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-53633
Is Your Infrastructure Affected by CVE-2026-53633?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.