| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pgf8-2hgj-grqg | Vercel: Non-interactive mode includes CLI arguments in suggested command output |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vercel
Vercel vercel |
|
| Vendors & Products |
Vercel
Vercel vercel |
Wed, 13 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), commands that cannot complete autonomously emit JSON payloads with suggested follow-up commands. If the user authenticated via --token or -t on the command line, the token value is included verbatim in those suggestions. The plaintext token may be captured in CI/CD logs, agent transcripts, or other automation output. This vulnerability is fixed in 52.0.1. | |
| Title | Vercel: Non-interactive mode includes CLI arguments in suggested command output | |
| Weaknesses | CWE-200 CWE-532 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T18:19:54.986Z
Reserved: 2026-05-06T17:18:51.782Z
Link: CVE-2026-44479
Updated: 2026-05-13T18:13:41.883Z
Status : Awaiting Analysis
Published: 2026-05-13T16:16:58.400
Modified: 2026-05-13T16:58:40.557
Link: CVE-2026-44479
No data.
OpenCVE Enrichment
Updated: 2026-05-13T18:15:16Z
Github GHSA