kokumօtօ[verified]@__kokumotoDisclosure
CVE‑2026‑53633 is a critical remote code execution flaw in Vitest with a CVSS score of 9.8; a PoC exists, the flaw exposes the Chrome DevTools Protocol via the cdp() API in browser mode, and a patch is available.
Upwind Security MDR[verified]@UpwindMDRDisclosure
CVE-2026-53633 reveals a critical RCE in Vitest Browser’s dev server when bound to the network, and the advisory recommends upgrading to patched versions to mitigate the flaw.
Daily CyberSecurity@the_yellow_fallPoC
The tweet reports a critical Vitest RCE (CVE‑2026‑53633, CVSS 9.8) with a publicly available PoC that demonstrates a Browser Mode config overwrite, but no evidence of active exploitation or patches is provided.
moton@motonPoC
A proof‑of‑concept for the Vitest RCE vulnerability CVE-2026-53633 (CVSS 9.8) has been released, but no evidence of active exploitation or a patch is provided.
DailyCVE@dailycveDisclosure
The text announces a critical authentication bypass vulnerability in Vitest Browser Mode (CVE-2026-53633) but provides no further details on exploitation, mitigation, or patches.