Critical [CVE-2026-73653] Browser Mode provider commands bypass the file-access permission gate
This critical-severity Red Hat Linux advisory covers CVE-2026-73653 affecting Red Hat Ansible Automation Platform 2, Red Hat Build of Keycloak, Red Hat Build of Podman Desktop.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root.
A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. A flaw was found in Vitest.
A remote attacker, by sending specially crafted commands to the Browser Mode API, could bypass file access restrictions. This allows the attacker to read, create, overwrite, or delete arbitrary files on the system where Vitest is running, even when file write permissions are explicitly disabled.
Red Hat severity: Critical — CVSS 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22.
Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Build of Podman Desktop.
Red Hat lists Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Trusted Artifact Signer as not affected.
- < 3.2.7
- < 4.1.10
- < 5.0.0-beta
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
- 3.2.7
- 4.1.10
- 5.0.0
- 5.0.0-beta
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- Making Browser Mode API unreachable outside of local machine by making it listen only on localhost.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.