PT-2026-71737 · Vitest · Vitest

CVE-2026-73653

·

Published

2026-07-21

·

Updated

2026-08-13

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Vitest versions prior to 3.2.7 Vitest versions prior to 4.1.10 Vitest versions prior to 5.0.0-beta.6
Description Browser Mode provider commands, specifically upload(), takeScreenshot(), screenshotMatcher(), stopChunkTrace(), deleteTracing(), and annotateTraces(), accept browser-supplied file paths without enforcing the allowWrite permission gate or restricting paths to the project root. This allows a client with access to the Browser Mode API to read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the process, even if allowWrite is set to false.
Recommendations Update to version 3.2.7 or later. Update to version 4.1.10 or later. Update to version 5.0.0-beta.6 or later.

Exploit

Fix

Files Accessible to External Parties

Path traversal

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73653
GHSA-P63J-VCC4-9VMV

Affected Products

Vitest