logo

9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers

ID: ac3b3274-5126-5175-81be-e388bba510e7

STIX ID: report--ac3b3274-5126-5175-81be-e388bba510e7

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Ddos

...
...

A critical command-injection vulnerability (CVE-2026-25244, CVSS 9.8) has been disclosed in WebdriverIO’s @wdio/browserstack-service: unsanitized git branch names are interpolated into execSync calls, allowing attackers who can supply a repository/branch name to execute arbitrary commands on developer machines and CI/CD build servers. Affected versions are up to and including 9.23.2; users should upgrade to 9.24.0 or later to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.