CVE-2026-25244

critical
Published 2026-05-18 · Modified 2026-05-19
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

WebdriverIO BrowserStack Service has a Command Injection issue

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/webdriverio/webdriverio/security/advisories/GHSA-5c46-x3qw-q7j7

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/webdriverio/webdriverio/releases/tag/v9.24.0

Package impact

EcosystemPackageVulnerableFixed
npm npm@wdio/browserstack-service<9.24.09.24.0
npm NPM@wdio/browserstack-service<= 9.23.29.24.0

Application impact

VendorProductVersionsFixed
openjsfwebdriverio{"endExcluding":"9.24.0"}9.24.0

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.