What is CVE-2026-47671?
In Nhost CLI versions prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and overly permissive CORS. This vulnerability could allow unauthorized requests to access sensitive data or manipulate the local development environment. Developers should immediately update Nhost CLI to version 1.46.0 or later.
Azərbaycanca: Nhost CLI-nin 1.46.0-dan əvvəlki versiyalarında, `nhost dev` əmri ilə işə salınan gizli `nhost configserver` Mimir GraphQL API-ni saxta avtorizasiya direktivləri və çox icazəli CORS ilə ifşa edir. Bu, lokal inkişaf mühitində işləyən tərtibatçıların məlumatlarının və ya mühitinin icazəsiz sorğulara qarşı həssas olmasına səbəb ola bilər. Tərtibatçılar dərhal Nhost CLI-ni 1.46.0 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Which versions of Nhost CLI are vulnerable to CVE-2026-47671?
Nhost CLI versions prior to 1.46.0 are vulnerable to this issue. Developers should immediately update Nhost CLI to version 1.46.0 or later.
How can CVE-2026-47671 affect the local development environment?
This vulnerability exposes the hidden `nhost configserver` Mimir GraphQL API, which is used by `nhost dev`, with dummy authorization directives and overly permissive CORS. This could make sensitive data in the local development environment susceptible to unauthorized requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.