{"id":"GHSA-9r75-g2cr-3h76","aliases":[],"url":"https://o3.security/vulnerability/GHSA-9r75-g2cr-3h76","summary":"Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens","details":"`createWebhook()` in Vercel Workflow DevKit accepts a user-specified `token` parameter that serves as the credential for the public webhook endpoint `/.well-known/workflow/v1/webhook/{token}`. Official documentation recommended predictable token patterns, making it possible for an unauthenticated remote attacker to guess the token and inject arbitrary payloads into the workflow execution context.\n\n#### Impact\n\nAn attacker who guesses a webhook token can resume the associated workflow with an attacker-controlled HTTP request body, potentially triggering downstream side effects such as API calls, database writes, or deployments.\n\n#### Fix\n\n* Upgrade to version 4.2.0-beta.64. The fix removes the `token` option from `createWebhook()` so that webhook tokens are always randomly generated by the SDK.\n* Runs created with versions prior to 4.2.0-beta.64, that are 1) still active (i.e. running), and 2) have open hooks, are still susceptible to this vulnerability. If users suspect the hook tokens are predictable or leaked - consider cancelling those runs and restarting them on the latest patch.\n\n#### Workarounds\n\nIn case a version upgrade is not possible, avoid passing predictable or guessable values to the `token` parameter of `createWebhook()`. Instead, users can either\n\n* switch from `createWebhook()` to `createHook()` instead and programmatically resume hooks using `resumeHook()` instead of the public webhook endpoint, or\n* use `createWebhook()` without passing a user-provided `token`, which uses a non-guessable random `nanoid` by default.","published":"2026-03-06T18:45:02Z","modified":"2026-03-06T19:02:20.219400Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"workflow","fixedVersion":"4.2.0-beta.64"},{"ecosystem":"npm","name":"@workflow/core","fixedVersion":"4.2.0-beta.64"}],"fix":{"url":"https://github.com/vercel/workflow/commit/30e24d441e735635ffa4522198e6905d0e51e175","label":"vercel/workflow@30e24d4"},"references":[{"type":"WEB","url":"https://github.com/vercel/workflow/security/advisories/GHSA-9r75-g2cr-3h76"},{"type":"WEB","url":"https://github.com/vercel/workflow/commit/30e24d441e735635ffa4522198e6905d0e51e175"},{"type":"PACKAGE","url":"https://github.com/vercel/workflow"},{"type":"WEB","url":"https://github.com/vercel/workflow/releases/tag/workflow%404.2.0-beta.64"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-06T19:02:20.219400Z"}}