---
cve: "CVE-2026-53633"
severity: "CRITICAL"
cvss: 9.8
epss: "58%"
vendor: "vitest-dev"
kev: false
exploited: false
published: "2026-07-14 19:35:42"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T03:10:04+02:00"
---

# CVE-2026-53633

> 9.8 CRITICAL · 🧪 PoC

## Beschreibung

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 2cbad0a923c48c6144266df3cd25f93547cb5221 (Commit)
- e61f2dd2a0ba0a266c1c5e0334aad3799fee527f (Commit)

## Referenzen

- <https://github.com/vitest-dev/vitest/security/advisories/GHSA-g8mr-85jm-7xhm>
- <https://github.com/vitest-dev/vitest/pull/10444>
- <https://github.com/vitest-dev/vitest/pull/10450>
- <https://github.com/vitest-dev/vitest/pull/10456>
- <https://github.com/vitest-dev/vitest/commit/385a1aefd4c2bfa5e7d58bf7c6834c929969f2c7>
- <https://github.com/vitest-dev/vitest/commit/63e3b2eee4d58da56786a6333f517b9b492528c7>
- <https://github.com/vitest-dev/vitest/commit/e4067b3b150005fd42cf75f994300119245806b9>
- <https://github.com/vitest-dev/vitest/releases/tag/v3.2.5>
- <https://github.com/vitest-dev/vitest/releases/tag/v4.1.8>
- <https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.4>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-53633) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
