logo

Vitest RCE Vulnerability (CVSS 9.8): Public PoC Disclosed for Testing Tool With 57M Weekly Downloads (CVE-2026-53633)

ID: 52cdc6c6-bfa5-549c-998d-c112e5841b3e

STIX ID: report--52cdc6c6-bfa5-549c-998d-c112e5841b3e

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

A critical RCE in Vitest (CVE-2026-53633, CVSS 9.8) allows attackers to use the Browser Mode cdp() API to execute raw CDP commands, overwrite vite.config.ts, and achieve host-level Node.js code execution; public exploit code is available and network-exposed Browser Mode significantly increases risk. Upgrades to patched releases (v4.1.8, v3.2.5, or v5.0.0-beta.4 for betas) are recommended and untrusted network exposure of Browser Mode should be avoided until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.