Vulnerabilities/

Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens

Severity:
Medium

Description

createWebhook() in Vercel Workflow DevKit accepts a user-specified token parameter that serves as the credential for the public webhook endpoint /.well-known/workflow/v1/webhook/{token}.

Recommendation

Update the @workflow/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@workflow/core
Anything's wrong? Let us know Last updated on March 06, 2026