mediumCVSS 5.3Vulnerability

GHSA-9r75-g2cr-3h76

`createWebhook()` in Vercel Workflow DevKit accepts a user-specified `token` parameter that serves as the credential for the public webhook endpoint `/.well-known/workflow/v1/webhook/{token}`. Official documentation recommended predictable token patterns, making it possible for an unauthenticated remote attacker to guess the token and inject arbitrary payloads into the workflow execution context. #### Impact An attacker who guesses a webhook token can resume the associated workflow with an attacker-controlled HTTP request body, potentially triggering downstream side effects such as API calls, database writes, or deployments. #### Fix * Upgrade to version 4.2.0-beta.64. The fix removes the `token` option from `createWebhook()` so that webhook tokens are always randomly generated by the SDK. * Runs created with versions prior to 4.2.0-beta.64, that are 1) still active (i.e. running), and 2) have open hooks, are still susceptible to this vulnerability. If users suspect the hook tokens are predictable or leaked - consider cancelling those runs and restarting them on the latest patch. #### Workarounds In case a version upgrade is not possible, avoid passing predictable or guessable values to the `token` parameter of `createWebhook()`. Instead, users can either * switch from `createWebhook()` to `createHook()` instead and programmatically resume hooks using `resumeHook()` instead of the public webhook endpoint, or * use `createWebhook()` without passing a user-provided `token`, which uses a non-guessable random `nanoid` by default.

Properties

ghsa_id
GHSA-9r75-g2cr-3h76
severity
medium
summary
Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens
cvss_score
5.3
cve_id
GHSA-9r75-g2cr-3h76
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-03-06T18:45:02Z
source_url
https://github.com/advisories/GHSA-9r75-g2cr-3h76
ghsa_updated
2026-03-06T18:45:02Z

Related Entities (4)

AFFECTS (2)

[Software]npm/workflow
[Software]npm/@workflow/core

HAS_WEAKNESS (1)

[Weakness]Improper Authentication

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph