CVE-2026-73653

@vitest/browser: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-73653)

criticalEPSS 0.8%

Affected

  • npm/@vitest/browser 4.0.0..*
  • npm/@vitest/browser 5.0.0-beta.1..*

Description

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

npm@vitest/browser
4.0.05.0.0-beta.1

Metrics

9.4
Source: cna-v3
54.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-13 18:19 UTC
CWE-22, CWE-552, CWE-862

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →
  • CWE-552Base

    Files or Directories Accessible to External Parties

    The product makes files or directories accessible to unauthorized actors, even though they should not be.

    cwe.mitre.org →
  • CWE-862Class

    Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

References & sources

Linked advisories