Untriaged
Permalink
CVE-2026-73653
9.4 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): Low (L)
Activity log
- Created suggestion
Vitest: Browser Mode provider commands bypass the file-access permission gate
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6.
References
-
https://github.com/vitest-dev/vitest/security/advisories/GHSA-p63j-vcc4-9vmv x_refsource_CONFIRM
-
https://github.com/vitest-dev/vitest/pull/10674 x_refsource_MISC
-
https://github.com/vitest-dev/vitest/pull/10679 x_refsource_MISC
-
https://github.com/vitest-dev/vitest/pull/10680 x_refsource_MISC
-
https://github.com/vitest-dev/vitest/releases/tag/v3.2.7 x_refsource_MISC
-
https://github.com/vitest-dev/vitest/releases/tag/v4.1.10 x_refsource_MISC
-
https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.6 x_refsource_MISC
Affected products
vitest
- ==>= 5.0.0-beta.1, < 5.0.0-beta.6
- ==>= 4.0.0, < 4.1.10
- ==< 3.2.7