Input Exposure Vulnerability in Vercel AI Cloud Platform
CVE-2026-44479

5.5MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44479?

Vercel's AI Cloud platform, versions 50.16.0 to 52.0.0, contains a vulnerability that occurs when running the Vercel CLI in non-interactive mode. In such scenarios, commands that cannot be executed autonomously generate JSON payloads that suggest follow-up commands. Importantly, if a user authenticates using a token via the command line, the token is included verbatim in these suggestions. This can lead to inadvertent exposure of the plaintext token in Continuous Integration/Continuous Deployment (CI/CD) logs or other automation outputs. The issue has been remediated in version 52.0.1.

Affected Version(s)

vercel >= 50.16.0, < 52.0.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.