CVE-2026-53633Disclosure

MEDIUM

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

4.0/ 10 priority

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-06-16)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-06-15: 1Mentions · 2026-06-16: 4PoC Mentioned / Linked · 2026-06-16: 3Exploit Tool / Code · 2026-06-16: 1Patch / Workaround · 2026-06-16: 2Technical Details · 2026-06-15: 1Technical Details · 2026-06-16: 406-1506-16
Signal classification2 categories
Disclosure
360.0%
PoC
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-151
Disclosure1
2026-06-164
Disclosure2PoC2
Full discourse5 posts
  • kokumօtօ@__kokumoto
    Disclosure

    Vitestに重大(Critical)な脆弱性。CVE-2026-53633はCVSSスコア9.8の遠隔コード実行。ブラウザモードでcdp() APIが生のChrome DevTools Protocolを晒しているもの。PoC(攻撃の概念実証コード)あり。修正版あり。 https://securityonline.info/vitest-rce-vulnerability-cve-2026-53633/

    Post summary

    CVE‑2026‑53633 is a critical remote code execution flaw in Vitest with a CVSS score of 9.8; a PoC exists, the flaw exposes the Chrome DevTools Protocol via the cdp() API in browser mode, and a patch is available.

    02063811
    7.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    PoC

    A critical Vitest RCE vulnerability (CVE-2026-53633, CVSS 9.8) has public PoC code. Browser Mode flaw enables config overwrite and remote code execution. #Vitest #CVE202653633 #RCE #npm #InfoSec https://securityonline.info/vitest-rce-vulnerability-cve-2026-53633 https://t.co/WoN2ymwrRj

    Post summary

    The tweet reports a critical Vitest RCE (CVE‑2026‑53633, CVSS 9.8) with a publicly available PoC that demonstrates a Browser Mode config overwrite, but no evidence of active exploitation or patches is provided.

    00021393
    12.8K followersView on X
  • moton@moton
    PoC

    Vitest RCE Vulnerability CVE-2026-53633 (CVSS 9.8), PoC Out - https://securityonline.info/vitest-rce-vulnerability-cve-2026-53633/

    Post summary

    A proof‑of‑concept for the Vitest RCE vulnerability CVE-2026-53633 (CVSS 9.8) has been released, but no evidence of active exploitation or a patch is provided.

    0000076
    660 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Vitest Browser Mode RCE via CDP Proxy (CVE-2026-53633) When @vitest/browser's dev server is bound to the network (--browser.api.host=0.0.0.0), the exposed cdp() API forwards raw Chrome DevTools Protocol over Vitest's WebSocket RPC. An attacker can use CDP to overwrite vite.config.ts and achieve remote code execution, bypassing allowWrite and allowExec restrictions entirely (CVSS 9.8). 👉 Affected: @vitest/browser 3.0.0–3.2.4, 4.0.0–4.1.7, 5.0.0-beta.0–beta.3 | Upgrade to 3.2.5 / 4.1.8 / 5.0.0-beta.4

    Post summary

    CVE-2026-53633 reveals a critical RCE in Vitest Browser’s dev server when bound to the network, and the advisory recommends upgrading to patched versions to mitigate the flaw.

    00000118
    217 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Vitest (Browser Mode), Authentication Bypass, #CVE-2026-53633 (Critical) -DC-Jun2026-434 https://dailycve.com/vitest-browser-mode-authentication-bypass-cve-2026-53633-critical-dc-jun2026-434/

    Post summary

    The text announces a critical authentication bypass vulnerability in Vitest Browser Mode (CVE-2026-53633) but provides no further details on exploitation, mitigation, or patches.

    0000038
    212 followersView on X

Explore more