HIGH 8.8 GitHub

CVE-2026-59160

@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run

## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Summary `@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run` HTTP endpoint exposed by this server performs no authentication, authorization, CSRF protection, or task allowlist check before executing attacker-supplied Turborepo task names via `spawn()`. Any adjacent-network attacker

Affected Products

References

Published: 2026-09-09 · Source: GitHub · Feed updated: 2026-09-11
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-09 via GitHub. Affected: npm/@yeger/turbo-graph <= 2.8.8.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.