PatchSiren cyber security CVE debrief
CVE-2026-46508 vercel CVE debrief
CVE-2026-46508 is a high-severity (CVSS 8.4) command injection vulnerability in the Turborepo Language Server Protocol (LSP) VS Code extension, published 2026-05-15 and last modified 2026-05-19. The extension, prior to version 2.9.14000, used string-based command execution for daemon commands and task runs, allowing malicious workspace-controlled values—such as crafted task names or workspace settings—to be interpolated into shell commands. When the extension activated or executed tasks, these values could be interpreted by the user's shell, resulting in arbitrary command execution with the privileges of the local VS Code process. The vulnerability is classified as CWE-77 (Command Injection) and has been remediated in version 2.9.14000. No known exploitation in the wild or ransomware campaign use has been reported.
- Vendor
- vercel
- Product
- turborepo
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-19
Who should care
Developers using the Turborepo LSP VS Code extension, particularly those working with repositories from external or untrusted sources. Security teams managing developer tooling and IDE extensions. Organizations with developers using Turborepo for JavaScript/TypeScript monorepo management.
Technical summary
The Turborepo LSP VS Code extension executed shell commands using string interpolation of workspace-controlled values. Malicious repositories could inject arbitrary shell commands through crafted task names or workspace settings, which would execute when the extension activated or ran tasks. The vulnerability required local access and user interaction (opening a workspace), but resulted in high impact to confidentiality, integrity, and availability of the VS Code process.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade the Turborepo LSP VS Code extension to version 2.9.14000 or later.
- Review workspace settings and task configurations in untrusted repositories before opening them in VS Code.
- Exercise caution when opening workspaces from untrusted sources, as malicious task names or settings could trigger command execution.
- Verify extension version via VS Code's Extensions panel and enable automatic updates for security patches.
Evidence notes
CVSS 4.0 vector: AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Affected versions: all versions prior to 2.9.14000 of the Turborepo LSP extension for Visual Studio Code. CPE: cpe:2.3:a:vercel:turborepo_language_server_protocol:*:*:*:*:*:visual_studio_code:*:*.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46508 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46508
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46508 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46508
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/vercel/turborepo/security/advisories/GHSA-5xc8-49mv-x4mm
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.