CVE-2026-8767
5.0 MEDIUMA vulnerability has been found in vercel ai up to 3.0.97
Published: 2026-05-17 · Last updated: 2026-05-19
Severity and scoring
- CVSS
- 5.0 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
- CWE
- CWE-77, CWE-78
Affected products
| Vendor | Product |
|---|---|
| vercel | ai |
Description
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2026-8769 — A vulnerability was determined in vercel ai up to 3.0.97 (4.3 MEDIUM)
- CVE-2026-8768 — A vulnerability was found in vercel ai up to 3.0.97 (7.3 HIGH)
- CVE-2026-46508 — Turborepo is a high-performance build system for JavaScript and TypeScript codebases (7.8 HIGH)
- CVE-2026-45773 — Turborepo is a high-performance build system for JavaScript and TypeScript codebases (6.5 MEDIUM)
- CVE-2026-45772 — Turborepo is a high-performance build system for JavaScript and TypeScript codebases (9.8 CRITICAL)
Same CWE
- CVE-2026-42846 — ClipBucket v5 is an open source video sharing platform (9.8 CRITICAL)
- CVE-2026-45172 — Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0....
- CVE-2026-48547 — KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands ... (7.3 HIGH)
- CVE-2026-49261 — MariaDB server is a community developed fork of MySQL server (10.0 CRITICAL)
- CVE-2026-49219 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)