Input Exposure Vulnerability in Vercel AI Cloud Platform
CVE-2026-44479
5.5MEDIUM
What is CVE-2026-44479?
Vercel's AI Cloud platform, versions 50.16.0 to 52.0.0, contains a vulnerability that occurs when running the Vercel CLI in non-interactive mode. In such scenarios, commands that cannot be executed autonomously generate JSON payloads that suggest follow-up commands. Importantly, if a user authenticates using a token via the command line, the token is included verbatim in these suggestions. This can lead to inadvertent exposure of the plaintext token in Continuous Integration/Continuous Deployment (CI/CD) logs or other automation outputs. The issue has been remediated in version 52.0.1.
Affected Version(s)
vercel >= 50.16.0, < 52.0.1