@vitest/browser vulnerabilities
CVEs whose affected-version data names the @vitest/browser package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-p63j-vcc4-9vmvCritical· 9.4@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
▾ Midnightvitest · @vitest/browservia GHSA
CVE-2026-53633Critical· 9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
▾ Midnightvitest · @vitest/browserEPSS 0.90%via GHSA