vitest has 3 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.4 (critical), with 2 rated critical. Most affected products: @vitest/browser (2), @vitest/mocker (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
Worst active — by depth score
CVE-2026-53633Critical· 9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE54GHSA-p63j-vcc4-9vmvCritical· 9.4@vitest/browser: Browser Mode provider commands bypass the file-access permission gate52CVE-2026-84373Medium· 5.9Vitest is a testing framework powered by Vite33
vitest vulnerabilities
CVEs affecting vitest, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-84373Medium· 5.9Vitest is a testing framework powered by Vite
Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:regi…
GHSA-p63j-vcc4-9vmvCritical· 9.4@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
CVE-2026-53633Critical· 9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE