CVE-2026-25244
WebdriverIO versions older than 9.24.0 allow attackers to inject shell commands via branch names, enabling remote code execution on CI/CD servers and developer machines. The flaw can expose credentials, source code, and SSH keys, and can be used for supply chain attacks.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
WebdriverIO test automation framework, versions below 9.24.0, used by developers and CI/CD pipelines.
Real-world impact
An attacker can run arbitrary shell commands on the machine running WebdriverIO, potentially stealing secrets, exfiltrating source code, compromising the system, and tampering with build artifacts.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited over the network with no authentication, no user interaction, and gives full confidentiality, integrity, and availability impact.
What to do about it
- 01Upgrade WebdriverIO to version 9.24.0 or later.
- 02Restart any services or pipelines that use WebdriverIO.
NVD-referenced vendor advisory
Timeline
- May 18, 2026 · May 18, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.