LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-46508

vercel · turborepo language server protocol

Published
CVSS7.8
Severityhigh
WeaknessCWE-77
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious workspace could provide crafted values through workspace settings or task names in the repository's source code that were interpolated into shell commands. When the extension activated or when a user ran a task through the extension, those values could be interpreted by the user's shell, allowing arbitrary command execution with the privileges of the local VS Code process. This

References

← Back to the CVE Tracker

Our coverage of CVE-2026-46508

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-46508.