CVE-2026-73653: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vitest-dev vitest
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6.
AI Analysis
Technical Summary
CVE-2026-73653 is a path traversal vulnerability in Vitest's Browser Mode provider commands (upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, annotateTraces). These commands improperly accept file paths from the browser without enforcing the allowWrite permission or confining file operations to the project root directory. As a result, an attacker who can access the Browser Mode API can perform unauthorized file read, write, and delete operations on the local filesystem accessible to the Vitest process. The vulnerability affects versions prior to 3.2.7, 4.1.10, and 5.0.0-beta.6, where it has been fixed.
Potential Impact
An attacker with access to the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process, even if the allowWrite permission is set to false. This can lead to unauthorized data disclosure, data tampering, and potential denial of service by deleting critical files. The CVSS score of 9.4 reflects the critical severity with network attack vector, no privileges or user interaction required, and high impact on confidentiality, integrity, and low impact on availability.
Mitigation Recommendations
Upgrade Vitest to version 3.2.7, 4.1.10, or 5.0.0-beta.6 or later, where this vulnerability is fixed. Until upgraded, restrict access to the Browser Mode API to trusted clients only. No official temporary fixes or workarounds are documented; patching is the recommended remediation.
CVE-2026-73653: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vitest-dev vitest
Description
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6.
CVSS v3.1
Score 9.4critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-73653 is a path traversal vulnerability in Vitest's Browser Mode provider commands (upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, annotateTraces). These commands improperly accept file paths from the browser without enforcing the allowWrite permission or confining file operations to the project root directory. As a result, an attacker who can access the Browser Mode API can perform unauthorized file read, write, and delete operations on the local filesystem accessible to the Vitest process. The vulnerability affects versions prior to 3.2.7, 4.1.10, and 5.0.0-beta.6, where it has been fixed.
Potential Impact
An attacker with access to the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process, even if the allowWrite permission is set to false. This can lead to unauthorized data disclosure, data tampering, and potential denial of service by deleting critical files. The CVSS score of 9.4 reflects the critical severity with network attack vector, no privileges or user interaction required, and high impact on confidentiality, integrity, and low impact on availability.
Mitigation Recommendations
Upgrade Vitest to version 3.2.7, 4.1.10, or 5.0.0-beta.6 or later, where this vulnerability is fixed. Until upgraded, restrict access to the Browser Mode API to trusted clients only. No official temporary fixes or workarounds are documented; patching is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-13T14:04:09.604Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7e0ff3bf8831d539a34e5d
Added to database: 08/13/2026, 18:41:55 UTC
Last enriched: 08/13/2026, 18:56:15 UTC
Last updated: 08/14/2026, 00:43:41 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.