Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Vercel CLI leaked auth tokens in AI-agent non-interactive command output (CVE-2026-44479)

Vercel CLI versions 50.16.0 through 52.0.0 embedded plaintext authentication tokens passed via --token/-t into JSON follow-up command suggestions emitted in non-interactive or auto-detected AI agent mode, risking token exposure in CI/CD logs and agent transcripts. The issue is fixed in version 52.0.1.

Disclosed 13 May 2026 · Record updated 13 September 2026

Impact

Plaintext API tokens could be captured in CI/CD logs, AI agent transcripts, or other automation output, potentially allowing account access to anyone able to read those logs.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44479