FixVibe

high

Command Injection in WebdriverIO BrowserStack Service (CVE-2026-25244)

WebdriverIO BrowserStack service versions up to and including 9.23.2 are affected by CVE-2026-25244 / GHSA-5c46-x3qw-q7j7. FixVibe repo scans flag affected @wdio/browserstack-service versions.

CVE-2026-25244GHSA-5c46-x3qw-q7j7CWE-78

Attacker Impact

Affected versions of @wdio/browserstack-service can expose OS command-injection risk when attacker-influenced BrowserStack Local or service configuration reaches the vulnerable WebdriverIO test-runner process [S2]. The practical blast radius is usually a CI runner, developer workstation, or test infrastructure host that has repository code, environment variables, and BrowserStack credentials available [S1]. A dependency match alone does not prove that the service is run, that untrusted users can influence its configuration, or that host compromise occurred.

Root Cause

The advisory covers @wdio/browserstack-service releases up to and including 9.23.2 [S2]. The vulnerable service handled BrowserStack-related options in a way that could cross a command-execution boundary when unsafe input was accepted by the test runner [S1]. Version 9.24.0 is the patched release listed by the advisory [S2].

Concrete Fixes

Upgrade @wdio/browserstack-service to 9.24.0 or newer, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild any CI image, devcontainer, package cache, or test-runner artifact that installs the dependency [S2]. Review BrowserStack credentials, environment variables, and untrusted pull-request workflows so untrusted code or configuration cannot control BrowserStack service options while secrets are available [S1]. If the affected service may have run in an untrusted CI context, review CI logs and rotate credentials appropriate to that environment.

Covered by FixVibe

FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve @wdio/browserstack-service versions affected by CVE-2026-25244 / GHSA-5c46-x3qw-q7j7 [S2], with the file, version and fixed version.