HIGH 8.8 GitHub
CVE-2026-59160
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run
### Summary
`@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run` HTTP endpoint exposed by this server performs no authentication, authorization, CSRF protection, or task allowlist check before executing attacker-supplied Turborepo task names via `spawn()`. Any adjacent-network attacker
Affected Products
- npm/@yeger/turbo-graph <= 2.8.8
References
- https://github.com/advisories/GHSA-2r5q-h53f-9rp3
- https://github.com/DerYeger/yeger/security/advisories/GHSA-2r5q-h53f-9rp3
- https://github.com/advisories/GHSA-2r5q-h53f-9rp3
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-09 via GitHub. Affected: npm/@yeger/turbo-graph <= 2.8.8.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.