PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25244 Openjsf CVE debrief

CVE-2026-25244 is a critical command injection issue in WebdriverIO versions below 9.24.0. The vulnerable path can pass Git branch names containing shell metacharacters into execSync() without sanitization through getGitMetadataForAISelection(), which can allow arbitrary command execution during test orchestration. The impact is especially serious for CI/CD runners and developer workstations that process untrusted repositories or repository state.

Vendor
Openjsf
Product
Webdriverio
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-18
Original CVE updated
2026-07-24
Advisory published
2026-05-18
Advisory updated
2026-07-24

Who should care

Teams using WebdriverIO for browser, E2E, component, or Appium-based testing should prioritize this if they run test orchestration against untrusted repositories, forks, branches, or working directories. CI/CD platform owners, build engineers, and developers who use the affected BrowserStack test orchestration path are the primary audience.

Technical summary

NVD classifies the issue as CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) with CWE-78. The vendor advisory and referenced source indicate that getGitMetadataForAISelection() interpolates Git branch names directly into execSync() calls. Because Git branch names can contain shell metacharacters, a malicious branch name in a repository supplied via testOrchestrationOptions.runSmartSelection.source, or from the current directory when unset, can trigger shell execution. The fixed release is 9.24.0.

Defensive priority

Immediate. Treat as a high-priority upgrade because the issue is network-reachable in common CI workflows, requires no privileges or user interaction, and can lead to full compromise of the execution environment.

Recommended defensive actions

  • Upgrade WebdriverIO to version 9.24.0 or later in all affected environments.
  • Audit CI/CD jobs and developer workflows that invoke the affected test orchestration path, especially where repositories or branches may be untrusted.
  • Review any automation that passes testOrchestrationOptions.runSmartSelection.source and ensure inputs cannot originate from untrusted repositories without controls.
  • Re-run builds or tests from a known-good environment after upgrading if there is any chance the vulnerable path was exercised.
  • Check for unexpected shell activity, altered build artifacts, or leaked credentials/secrets in environments that processed potentially malicious branch names.
  • Use least-privilege credentials for test runners and isolate CI jobs to reduce blast radius if similar issues recur.

Evidence notes

This debrief is based only on the supplied CVE/NVD corpus and linked official references. The CVE record was published at 2026-05-18T21:16:39.547Z and modified at 2026-05-19T21:08:29.203Z. The NVD entry lists WebdriverIO (OpenJSF CPE), vulnerability status Analyzed, CWE-78, and an affected version range ending before 9.24.0. The referenced source line and vendor advisory support the unsanitized execSync() interpolation claim, and the 9.24.0 release is identified as the fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25244 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25244

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25244 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25244

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.