{"id":"GHSA-pgf8-2hgj-grqg","summary":"Vercel: Non-interactive mode includes CLI arguments in suggested command output","details":"# Summary\n\nWhen the Vercel CLI runs in non-interactive mode (`--non-interactive` or auto-detected AI agent), commands that cannot complete autonomously emit JSON payloads with suggested follow-up commands. If the user authenticated via `--token` or `-t` on the command line, the token value is included verbatim in those suggestions.\n\n# Conditions\n\nAll three must be true for the token to appear in output:\n\n1. Token passed as a CLI argument (`--token` / `-t`). The `VERCEL_TOKEN` environment variable is **not affected**.\n2. Non-interactive mode is active (explicit flag or AI agent auto-detection).\n3. The command cannot complete on its own (e.g. missing `--yes`, ambiguous scope, API errors). Successful commands produce no suggestion output.\n\n## Impact\n\nThe plaintext token may be captured in CI/CD logs, agent transcripts, or other automation output.\n\n## Remediation\n\n- Upgrade to the patched version.\n- If developers have previously used `--token` with `--non-interactive` in their applications, review logs for exposed tokens and rotate them.\n- Prefer `VERCEL_TOKEN` environment variable for authentication.","aliases":["CVE-2026-44479"],"modified":"2026-05-14T20:52:08.148951Z","published":"2026-05-07T00:05:20Z","database_specific":{"cwe_ids":["CWE-200","CWE-532"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-07T00:05:20Z","nvd_published_at":"2026-05-13T16:16:58Z"},"references":[{"type":"WEB","url":"https://github.com/vercel/vercel/security/advisories/GHSA-pgf8-2hgj-grqg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44479"},{"type":"PACKAGE","url":"https://github.com/vercel/vercel"}],"affected":[{"package":{"name":"vercel","ecosystem":"npm","purl":"pkg:npm/vercel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"50.16.0"},{"fixed":"52.0.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 52.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pgf8-2hgj-grqg/GHSA-pgf8-2hgj-grqg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}