Skip to main content
VercelLaunch

Turborepo 2.9.14 patches VS Code extension command injection.

What happened

Vercel Inc. launches Turborepo v2.9.14.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Turborepo 2.9.14 patches VS Code extension command injection. Vercel shipped Turborepo v2.9.14 today. Under the CI and docs churn sits a blunt security note worth catching even if your monorepo never touches turbo on the CLI: the VS Code Turborepo / LSP extension carries fixes for multiple advisories, and the headline item is GHSA-5xc8-49mv-x4mm (CVE-2026-46508, rated High). Where the hole actually lived. Upstream's wording is sober. Older extension builds routed some daemon and task-runner work through string-shaped shell commands. Values that a repo can steer (workspace configuration, names of tasks surfaced from the codebase) fed into those strings. Activate the extension against a hostile clone, or run a task through the extension UI after those values loaded, and the host shell could interpret the payload as arbitrary commands running with whatever rights the VS Code process already has. This is classic "IDE extension meets untrusted workspace" territory. The precondition is simpler than chasing a zero-day broker: convincing someone to open your repo locally plus enough interaction that the extension does its job. What changed in practical terms. GitHub lists the patched band as >= 2.9.14000 for the Turborepo LSP package and summarizes the remediation as ditching brittle shell interpolation (execFile with explicit argv for daemon hooks, structured terminal...

Keep reading with a free account

The rest of this article, and every signal for Vercel, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Product
Turborepo v2.9.14

The full record

From the Signal API record

Extraction

Confidence
39%
Detected
May 14, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Vercel and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Vercel this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/247f0118-a117-4df6-bfec-e8d2e078ec63 returns this record as JSON. POST /v1/companies/enrich returns every signal for vercel.com.

{
  "signal_id": "247f0118-a117-4df6-bfec-e8d2e078ec63",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-05-14T12:00:00+00:00",
  "company": {
    "name": "Vercel",
    "domain": "vercel.com"
  },
  "data": {
    "url": "https://www.osbytes.io/blog/turborepo-2-9-14-patches-vs-code-extension-command-injection",
    "title": "Turborepo 2.9.14 patches VS Code extension command injection.",
    "excerpt": "Turborepo 2.9.14 patches VS Code extension command injection.\n\nVercel shipped Turborepo v2.9.14 today. Under the CI and docs churn sits a blunt security note worth catching even if your monorepo never touches turbo on the CLI: the VS Code Turborepo / LSP extension carries fixes for multiple advisories, and the headline item is GHSA-5xc8-49mv-x4mm (CVE-2026-46508, rated High).\n\nWhere the hole actually lived.\n\nUpstream's wording is sober. Older extension builds routed some daemon and task-runner work through string-shaped shell commands. Values that a repo can steer (workspace configuration, names of tasks surfaced from the codebase) fed into those strings. Activate the extension against a hostile clone, or run a task through the extension UI after those values loaded, and the host shell could interpret the payload as arbitrary commands running with whatever rights the VS Code process already has.\n\nThis is classic \"IDE extension meets untrusted workspace\" territory. The precondition is simpler than chasing a zero-day broker: convincing someone to open your repo locally plus enough interaction that the extension does its job.\n\nWhat changed in practical terms.\n\nGitHub lists the patched band as >= 2.9.14000 for the Turborepo LSP package and summarizes the remediation as ditching brittle shell interpolation (execFile with explicit argv for daemon hooks, structured terminal launches...",
    "product": "Turborepo v2.9.14",
    "summary": "Vercel Inc. launches Turborepo v2.9.14.",
    "planning": false,
    "image_url": "https://www.osbytes.io/blog/turborepo-2-9-14-patches-vs-code-extension-command-injection/opengraph-image?85e173741555b7b1",
    "confidence": 0.3858,
    "product_data": {
      "full_text": "Turborepo v2.9.14",
      "fuzzy_match": true
    },
    "published_at": "2026-05-14T12:00:00Z",
    "article_sentence": "Vercel shipped Turborepo v2.9.14 today."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.