CVE-2026-25244Disclosure(openjsf / webdriverio)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openjsf webdriverio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and getGitMetadataForAISelection() interpolates these names directly into execSync() calls without sanitization. An attacker can exploit this by supplying a malicious repository (via testOrchestrationOptions.runSmartSelection.source, or the current directory if unset) whose branch name carries a payload, causing the shell to execute arbitrary code. This enables remote code execution on CI/CD servers and developer machines, leading to credential and secret disclosure, source code and SSH key exfiltration, system compromise, and supply chain attacks via tampered build artifacts. The issue has been fixed in version 9.24.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webdriverio

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-19); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
webdriverio

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-05-13: 2Mentions · 2026-05-19: 3Mentions · 2026-05-21: 1Mentions · 2026-06-03: 1Patch / Workaround · 2026-05-13: 2Technical Details · 2026-05-13: 2Technical Details · 2026-05-19: 3Technical Details · 2026-05-21: 1Technical Details · 2026-06-03: 105-1305-1905-2106-03
Signal classification3 categories
Disclosure
342.9%
Patch
228.6%
General
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-132
Patch2
2026-05-193
Disclosure2General1
2026-05-211
Disclosure1
2026-06-031
General1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical Alert: CVE-2026-25244 (CVSS 9.8) in WebdriverIO allows RCE via unsanitized git branch names. Secure your CI/CD pipeline and update to 9.24.0 now. #WebdriverIO #CyberSecurity #InfoSec #RCE #DevOps #CICD #VulnerabilityAlert #CVE https://securityonline.info/webdriverio-command-injection-vulnerability-cve-2026-25244/ https://t.co/VPB49yvWuB

    Post summary

    The alert warns of a critical RCE vulnerability (CVE-2026-25244) in WebdriverIO caused by unsanitized git branch names, recommends immediate update to version 9.24.0, and provides basic technical details.

    02061344
    12.5K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-25244: WebdriverIO Command Injection Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04jVBPk0

    Post summary

    The article announces CVE‑2026‑25244, a WebdriverIO command injection vulnerability, and discusses business implications and response strategies, but it does not provide PoC, exploit code, active exploitation details, or patch information.

    0000029
    32 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-25244: Critical RCE Flaw Hits WebdriverIO BrowserStack https://thecybrdef.com/cve-2026-25244-critical-rce-flaw-hits-webdriverio-browserstack/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    CVE-2026-25244 is disclosed as a critical remote code execution flaw affecting WebdriverIO used by BrowserStack, with no PoC, exploit code, or patch details provided.

    0000054
    9 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-25244 WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command inj… https://www.cve.org/CVERecord?id=CVE-2026-25244 ----- Traducción: CVE-2026-25244 Web… http://infoflow.cloud`

    Post summary

    The post mentions CVE-2026-25244 for WebdriverIO, noting that earlier versions are vulnerable to command injection, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000066
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25244 WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command inj… https://www.cve.org/CVERecord?id=CVE-2026-25244

    Post summary

    The statement announces a command injection vulnerability in WebdriverIO versions below 9.24.0, highlighting the affected component but providing no exploit or mitigation details.

    00000209
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25244 Command Injection Remote Code Execution in WebdriverIO Below 9.24.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25244 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The note announces that CVE-2026-25244 is a command‑injection‑based remote code execution vulnerability affecting WebdriverIO below version 9.24.0, linking to monitoring pages but offering no PoC, exploit code, or mitigation details.

    0000057
    4.0K followersView on X
  • Cyber Netsec IO@NetSecIO
    Patch

    Critical 9.8 CVSS command injection flaw (CVE-2026-25244) found in WebdriverIO. Malicious git branch names can lead to CI/CD server takeover. If you use @wdio/browserstack-service, update immediately! 🚨 #CyberSecurity #SupplyChain #DevSecOps https://t.co/LR3eLdmhkw

    Post summary

    The tweet announces a critical CVE-2026-25244 command‑injection flaw in WebdriverIO that can lead to CI/CD server takeover via malicious git branch names and urges users of @wdio/browserstack-service to update immediately.

    0000044
    53 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsfwebdriverio-node.js-

Explore more