Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
A critical security flaw (CVE-2026-47428) was found in Vitest Browser Mode, allowing remote attackers to execute arbitrary JavaScript code via a crafted browser-runner URL. This could lead to unauthorized access to the VITEST_API_TOKEN and further system compromise. However, Red Hat products do not ship or enable the vulnerable @vitest/browser package or Browser Mode, and Vitest is only used as a build/test-time dependency without Browser Mode enabled. Therefore, Red Hat products are not affected by this vulnerability. No mitigation is required for Red Hat shipping products. Development teams using Vitest should avoid enabling Browser Mode and upgrade to Vitest versions 4.1.6 or later.
AI Analysis
Technical Summary
CVE-2026-47428 is a vulnerability in Vitest's Browser Mode that permits remote code execution through a specially crafted browser-runner URL. This flaw can also expose the VITEST_API_TOKEN, enabling unauthorized authenticated API calls. Red Hat has confirmed that none of its shipping products install or enable the vulnerable @vitest/browser package or Browser Mode; Vitest is used only as a build/test-time devDependency without Browser Mode. Several affected Vitest streams have been patched in versions 4.1.6 and above. Consequently, Red Hat products are not reachable via this vulnerability. The advisory also references CVE-2026-47429 and includes fixes in Red Hat Hardened Images RPMs for prometheus3.13 packages, but no direct fixes for this CVE are needed in Red Hat products.
Potential Impact
If exploited in an environment where Vitest Browser Mode is enabled, this vulnerability allows remote attackers to execute arbitrary JavaScript code on the Vitest server and potentially access sensitive tokens, leading to unauthorized API calls and system compromise. However, Red Hat products do not include or enable the vulnerable component, so there is no impact on Red Hat shipping products. The vulnerability is critical in general but does not affect Red Hat's delivered software.
Mitigation Recommendations
No mitigation is required for Red Hat shipping products because the vulnerable @vitest/browser package and Browser Mode are not present or enabled. Development teams using Vitest as a build/test-time dependency should avoid introducing @vitest/browser or enabling Browser Mode in CI or local environments. They should upgrade to Vitest version 4.1.6 or later (or 5.0.0-beta.3 on the beta line) to ensure patched versions are used.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A critical security flaw (CVE-2026-47428) was found in Vitest Browser Mode, allowing remote attackers to execute arbitrary JavaScript code via a crafted browser-runner URL. This could lead to unauthorized access to the VITEST_API_TOKEN and further system compromise. However, Red Hat products do not ship or enable the vulnerable @vitest/browser package or Browser Mode, and Vitest is only used as a build/test-time dependency without Browser Mode enabled. Therefore, Red Hat products are not affected by this vulnerability. No mitigation is required for Red Hat shipping products. Development teams using Vitest should avoid enabling Browser Mode and upgrade to Vitest versions 4.1.6 or later.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-47428 is a vulnerability in Vitest's Browser Mode that permits remote code execution through a specially crafted browser-runner URL. This flaw can also expose the VITEST_API_TOKEN, enabling unauthorized authenticated API calls. Red Hat has confirmed that none of its shipping products install or enable the vulnerable @vitest/browser package or Browser Mode; Vitest is used only as a build/test-time devDependency without Browser Mode. Several affected Vitest streams have been patched in versions 4.1.6 and above. Consequently, Red Hat products are not reachable via this vulnerability. The advisory also references CVE-2026-47429 and includes fixes in Red Hat Hardened Images RPMs for prometheus3.13 packages, but no direct fixes for this CVE are needed in Red Hat products.
Potential Impact
If exploited in an environment where Vitest Browser Mode is enabled, this vulnerability allows remote attackers to execute arbitrary JavaScript code on the Vitest server and potentially access sensitive tokens, leading to unauthorized API calls and system compromise. However, Red Hat products do not include or enable the vulnerable component, so there is no impact on Red Hat shipping products. The vulnerability is critical in general but does not affect Red Hat's delivered software.
Mitigation Recommendations
No mitigation is required for Red Hat shipping products because the vulnerable @vitest/browser package and Browser Mode are not present or enabled. Development teams using Vitest as a build/test-time dependency should avoid introducing @vitest/browser or enabling Browser Mode in CI or local environments. They should upgrade to Vitest version 4.1.6 or later (or 5.0.0-beta.3 on the beta line) to ensure patched versions are used.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:39058
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-47429"]
- Cvss Version
- null
Threat ID: 6a5d27b32a4a8d598913360f
Added to database: 07/19/2026, 19:38:27 UTC
Last enriched: 08/24/2026, 16:07:56 UTC
Last updated: 09/03/2026, 10:52:09 UTC
Views: 100
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.