PatchSiren cyber security CVE debrief
CVE-2026-8767 vercel CVE debrief
A command injection vulnerability exists in Vercel AI SDK versions up to 3.0.97, specifically within a GitHub Actions workflow file. The vulnerability resides in the `run` function of `.github/workflows/prettier-on-automerge.yml`, where PR branch name interpolation allows for OS command injection. The attack vector is remote but requires high complexity and difficult exploitability conditions. The CVSS 4.0 score of 1.3 reflects these constraints. The exploit has been publicly disclosed, and the vendor was reportedly contacted without response. The vulnerability affects the CPE `cpe:2.3:a:vercel:ai:*:*:*:*:*:*:*:*` with versions up to and including 3.0.97.
- Vendor
- vercel
- Product
- ai
- CVSS
- LOW 1.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-17
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-17
- Advisory updated
- 2026-05-19
Who should care
Organizations using Vercel AI SDK versions ≤3.0.97 with automated workflows triggered by pull requests; security teams responsible for CI/CD pipeline security; developers maintaining GitHub Actions workflows with user-controlled input
Technical summary
The vulnerability exists in a GitHub Actions workflow file where PR branch names are interpolated directly into shell commands without proper sanitization. This allows an attacker with the ability to create pull requests with maliciously crafted branch names to execute arbitrary OS commands within the workflow runner context. The attack requires the ability to create PRs and depends on the specific workflow trigger conditions.
Defensive priority
LOW
Recommended defensive actions
- Review and sanitize all user-controlled inputs in GitHub Actions workflows, particularly branch names and PR metadata used in shell commands
- Update Vercel AI SDK to version 3.0.98 or later when available
- Audit `.github/workflows/prettier-on-automerge.yml` and similar workflow files for unsafe interpolation patterns
- Implement branch name validation rules in repository settings to reject branch names containing shell metacharacters
- Consider using GitHub Actions security hardening practices including `set -euo pipefail` and avoiding direct variable interpolation in shell commands
- Monitor for suspicious workflow runs or unauthorized repository access attempts
Evidence notes
Vulnerability data sourced from NVD with VulDB as CNA. CPE criteria confirms affected product as Vercel AI up to version 3.0.97. CVSS 4.0 vector indicates network attack vector with high attack complexity, low privileges required, and no user interaction. Weaknesses mapped to CWE-77 (Command Injection) and CWE-78 (OS Command Injection).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8767 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8767
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8767 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8767
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gist.github.com/YLChen-007/870bd6966cd84703d91ce54dfea3bdd0
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/811402
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/vuln/364392
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/364392/cti
[email protected] - Permissions Required, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.