9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers
ID: ac3b3274-5126-5175-81be-e388bba510e7
STIX ID: report--ac3b3274-5126-5175-81be-e388bba510e7
Feed Name: securityonline.info
Threat Score
A critical command-injection vulnerability (CVE-2026-25244, CVSS 9.8) has been disclosed in WebdriverIO’s @wdio/browserstack-service: unsanitized git branch names are interpolated into execSync calls, allowing attackers who can supply a repository/branch name to execute arbitrary commands on developer machines and CI/CD build servers. Affected versions are up to and including 9.23.2; users should upgrade to 9.24.0 or later to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
