<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 03:27:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368782</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368782</link>
      <description>EUVD-2026-368782</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368782</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59160</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59160</link>
      <description>&lt;p&gt;Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The handler accepts the tasks, filter, and force query parameters, and buildResponseFromArgs passes attacker-selected task names to spawn() as Turbo CLI arguments. An adjacent-network attacker can execute any task defined in the victim repository&amp;#39;s turbo.json with the privileges of the developer OS user, potentially exposing secrets, modifying files or infrastructure, or causing destructive availability effects. The use of an argument array prevents traditional shell metacharacter injection but does not prevent unauthorized execution of defined tasks. This issue is fixed in version 2.8.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The handler accepts the tasks, filter, and force query parameters, and buildResponseFromArgs passes attacker-selected task names to spawn() as Turbo CLI arguments. An adjacent-network attacker can execute any task defined in the victim repository&amp;#39;s turbo.json with the privileges of the developer OS user, potentially exposing secrets, modifying files or infrastructure, or causing destructive availability effects. The use of an argument array prevents traditional shell metacharacter injection but does not prevent unauthorized execution of defined tasks. This issue is fixed in version 2.8.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59160</guid>
    </item>
    <item>
      <title>GHSA-2r5q-h53f-9rp3 — @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2r5q-h53f-9rp3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @yeger/turbo-graph&lt;/p&gt;
&lt;p&gt;## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run` HTTP endpoint exposed by this server performs no authentication, authorization, CSRF protection, or task allowlist check before executing attacker-supplied Turborepo task names via `spawn()`. Any adjacent-network attacker can send an unauthenticated GET request to trigger arbitrary tasks defined in the victim&amp;#39;s repository, resulting in code execution, file modification, destructive build side effects, or deployment of attacker-chosen targets with the privileges of the developer&amp;#39;s OS user.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Two independent flaws combine to create a remotely exploitable unauthenticated code execution vulnerability:&lt;/p&gt;
&lt;p&gt;**Flaw 1 — Server bound to all interfaces (not loopback)**&lt;/p&gt;
&lt;p&gt;`packages/turbo-graph/src/index.ts:44` calls `.listen(options.port, callback)` without passing a hostname argument. Although `const hostname = &amp;#39;localhost&amp;#39;` is declared at line 19, it is used only for constructing the console log URL and is never passed to `listen()`. Node.js therefore defaults to binding on `0.0.0.0` (all IPv4 interfaces) and `::` (all IPv6 interfaces), making the server reachable from the local network segment.&lt;/p&gt;
&lt;p&gt;```ts
// packages/turbo-graph/src/index.ts
19    const hostname = &amp;#39;localhost&amp;#39;  // used only for console URL,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @yeger/turbo-graph&lt;/p&gt;
&lt;p&gt;## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run` HTTP endpoint exposed by this server performs no authentication, authorization, CSRF protection, or task allowlist check before executing attacker-supplied Turborepo task names via `spawn()`. Any adjacent-network attacker can send an unauthenticated GET request to trigger arbitrary tasks defined in the victim&amp;#39;s repository, resulting in code execution, file modification, destructive build side effects, or deployment of attacker-chosen targets with the privileges of the developer&amp;#39;s OS user.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Two independent flaws combine to create a remotely exploitable unauthenticated code execution vulnerability:&lt;/p&gt;
&lt;p&gt;**Flaw 1 — Server bound to all interfaces (not loopback)**&lt;/p&gt;
&lt;p&gt;`packages/turbo-graph/src/index.ts:44` calls `.listen(options.port, callback)` without passing a hostname argument. Although `const hostname = &amp;#39;localhost&amp;#39;` is declared at line 19, it is used only for constructing the console log URL and is never passed to `listen()`. Node.js therefore defaults to binding on `0.0.0.0` (all IPv4 interfaces) and `::` (all IPv6 interfaces), making the server reachable from the local network segment.&lt;/p&gt;
&lt;p&gt;```ts
// packages/turbo-graph/src/index.ts
19    const hostname = &amp;#39;localhost&amp;#39;  // used only for console URL,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2r5q-h53f-9rp3</guid>
    </item>
  </channel>
</rss>
