What is CVE-2026-73653?
CVE-2026-73653 is a vulnerability found in the Vitest testing framework where Browser Mode commands fail to enforce the 'allowWrite' restriction on browser-supplied file paths. This allows for remote code execution (RCE), requiring an immediate update to versions 3.2.7, 4.1.10, or 5.0.0-beta.6.
Azərbaycanca: CVE-2026-73653 Vitest sınaq frameworkündə aşkar edilmiş boşluqdur. Brauzer rejimindəki bəzi əmrlər 'allowWrite' məhdudiyyətini tətbiq etmədən brauzerdən gələn fayl yolunu qəbul edir. Bu zəiflikdən istifadə edərək uzaqdan kod icrası (RCE) mümkündür, ona görə də Vitest-i təcili olaraq 3.2.7, 4.1.10 və ya 5.0.0-beta.6 versiyalarına yeniləmək lazımdır.
FAQ2
What is CVE-2026-73653?
CVE-2026-73653 is a vulnerability found in the Vitest testing framework where Browser Mode commands accept browser-supplied file paths without enforcing the 'allowWrite' restriction.
Which versions of Vitest should be updated to?
Due to CVE-2026-73653, Vitest must be immediately updated to versions 3.2.7, 4.1.10, or 5.0.0-beta.6.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.