4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether @vitest/browser is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.4
CVE-2026-73653
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
CRITICAL 9.6
CVE-2026-47428
Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
CRITICAL 9.8
CVE-2026-53633
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
MEDIUM 5.9
CVE-2025-24963
Vitest browser mode serves arbitrary files
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes