Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens - workflow
- Severity:
- Medium
Description
createWebhook() in Vercel Workflow DevKit accepts a user-specified token parameter that serves as the credential for the public webhook endpoint /.well-known/workflow/v1/webhook/{token}.
Recommendation
Update the workflow package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.1.0-beta.63
- Patched version(s): 4.2.0-beta.64
References
Related Issues
- Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens - Vulnerability
- @saltcorn/data: Tenant user role is used for tenant creation role check - Vulnerability
- Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters - Vulnerability
- SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user - CVE-2026-34524
You might also like:
- Tags:
- npm
- workflow
Anything's wrong? Let us know Last updated on March 06, 2026


