CVE-2026-59160
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The handler accepts the tasks, filter, and force query parameters, and buildResponseFromArgs passes attacker-selected task names to spawn() as Turbo CLI arguments. An adjacent-network attacker can execute any task defined in the victim repository's turbo.json with the privileges of the developer OS user, potentially exposing secrets, modifying files or infrastructure, or causing destructive availability effects. The use of an argument array prevents traditional shell metacharacter injection but does not prevent unauthorized execution of defined tasks. This issue is fixed in version 2.8.9.
Not on KEV
Not in CISA's Known Exploited Vulnerabilities catalogue as of the last daily pull. Absence is not proof of safety.
0%
Chance of exploitation in the next 30 days, 35th percentile of all CVEs. A forecast; KEV outranks it.
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
—
No exposure census on this CVE's dispatches.
- nvd.nist.gov ↗
- first.org · EPSS ↗
- github.com/DerYeger/yeger/commit/a6c41db6b575cccdd8ff89dbe8ce1792ad062852 ↗
- github.com/DerYeger/yeger/releases/tag/@yeger/turbo-graph@2.8.9 ↗
- github.com/DerYeger/yeger/security/advisories/GHSA-2r5q-h53f-9rp3 ↗
- github.com/DerYeger/yeger/security/advisories/GHSA-2r5q-h53f-9rp3 ↗
Watch this one?
Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.