A vulnerability labeled as critical has been found in WebdriverIO up to 9.23.x . This issue affects the function getGitMetadataForAISelection . The manipulation results in os command injection. This vulnerability is known as CVE-2026-25244 . It is possible to launch the attack remotely. No exploit is available. The affected component should be upgraded.