GHSA-2r5q-h53f-9rp3
HIGHCVE-2026-59160@yeger/turbo-graph starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (0.0.0.0:29312 by default). The /api/run HTTP endpoint exposed by this server performs no authentication, authorization, CSRF protection, or task allowlist check before executing attacker-supplied Turborepo task names via spawn(). Any adjacent-network atta
- Affected
- >=0, <2.8.12, <= 2.8.8
- Fixed in
- 2.8.12
- Weakness
- CWE-306
- Published
- 2026-09-09
- Source
- osv