Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5c46-x3qw-q7j7 | WebdriverIO BrowserStack Service has a Command Injection issue |
Fri, 22 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 19 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openjsf
Openjsf webdriverio |
|
| CPEs | cpe:2.3:a:openjsf:webdriverio:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openjsf
Openjsf webdriverio |
Tue, 19 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webdriverio
Webdriverio webdriverio |
|
| Vendors & Products |
Webdriverio
Webdriverio webdriverio |
Mon, 18 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and getGitMetadataForAISelection() interpolates these names directly into execSync() calls without sanitization. An attacker can exploit this by supplying a malicious repository (via testOrchestrationOptions.runSmartSelection.source, or the current directory if unset) whose branch name carries a payload, causing the shell to execute arbitrary code. This enables remote code execution on CI/CD servers and developer machines, leading to credential and secret disclosure, source code and SSH key exfiltration, system compromise, and supply chain attacks via tampered build artifacts. The issue has been fixed in version 9.24.0. | |
| Title | WebdriverIO has Command Injection in the BrowserStack Service | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-30T12:06:34.604Z
Reserved: 2026-01-30T14:44:47.330Z
Link: CVE-2026-25244
Updated: 2026-06-30T02:46:18.737Z
Status : Analyzed
Published: 2026-05-18T21:16:39.547
Modified: 2026-06-17T10:24:22.220
Link: CVE-2026-25244
OpenCVE Enrichment
Updated: 2026-06-30T16:15:06Z
Github GHSA