Skip to content
VulniPulse
Critical9.4Red Hat Linux

Critical [CVE-2026-73653] Browser Mode provider commands bypass the file-access permission gate

This critical-severity Red Hat Linux advisory covers CVE-2026-73653 affecting Red Hat Ansible Automation Platform 2, Red Hat Build of Keycloak, Red Hat Build of Podman Desktop.

CVE-2026-73653 Published Aug 13, 2026Updated by vendor Aug 13, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root.

A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. A flaw was found in Vitest.

A remote attacker, by sending specially crafted commands to the Browser Mode API, could bypass file access restrictions. This allows the attacker to read, create, overwrite, or delete arbitrary files on the system where Vitest is running, even when file write permissions are explicitly disabled.

Red Hat severity: Critical — CVSS 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22.

Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Build of Podman Desktop.

Red Hat lists Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Trusted Artifact Signer as not affected.

Affected versions
  • < 3.2.7
  • < 4.1.10
  • < 5.0.0-beta

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Fixed versions
  • 3.2.7
  • 4.1.10
  • 5.0.0
  • 5.0.0-beta

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Making Browser Mode API unreachable outside of local machine by making it listen only on localhost.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.