CVE-2026-73653
CriticalAdvisory
Published 21 Jul 2026In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.4
- base score, highest
- EPSS
- 0.006
- 49th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 5
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 1 of 1
- affected package
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| @vitest/ | 2.0.4, 4.0.7, 4.0.9, 4.1.7+1 more | 3.2.7, 4.1.10 | 5 |
- OSV records
- GHSA-p63j-vcc4-9vmv
Charts affected
5 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| openclawopenclaw-helmVerified publisher | 1.5.40 | 1 of 2See more | 5,660 |
| openclaw-with-brainopenclaw-with-brainVerified publisher | 0.1.67 | 1 of 3See more | 5,218 |
| ethereumjsethereum-helm-chartsVerified publisher | 0.1.2 | 1 of 2See more | 1,442 |
| lodestarethereum-helm-chartsVerified publisher | 1.2.2 | 1 of 2See more | 2,522 |
| lodestar-validatorstakewise | 1.2.0 | 1 of 1See more | 4,052 |
Container images carrying it
5 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| chainsafe/ | 5593f6e97912 | @vitest/ | 4.1.10 | 1 |
| chainsafe/ | 7b9fe4aa8073 | @vitest/ | 3.2.7 | 1 |
| ethpandaops/ | fb84b718500f | @vitest/ | 4.1.10 | 1 |
| ghcr.io/ | af7ea052cf21 | @vitest/ | 4.1.10 | 1 |
| ghcr.io/ | dcfd14877740 | @vitest/ | 4.1.10 | 1 |