OS Command Injection Vulnerability in Vercel AI Product
CVE-2026-8767
Key Information:
Badges
What is CVE-2026-8767?
A vulnerability has been discovered in Vercel AI versions up to 3.0.97, specifically affecting the function run found in the .github/workflows/prettier-on-automerge.yml file. This flaw allows an attacker to manipulate the system through os command injection. The vulnerability can potentially be exploited remotely, although executing such an attack involves a high level of complexity. Despite early notifications to the vendor, Vercel has not responded or issued a remediation, leaving systems vulnerable to the disclosed exploit.
Affected Version(s)
ai 3.0.0
ai 3.0.1
ai 3.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved