CVE-2026-59160 (CVSS 8.8 – High): A missing authentication vulnerability (CWE-306) exists in the /api/run endpoint. The embedded Next.js server listens on all network interfaces by default, while the endpoint performs no authentication, authorization, CSRF protection, or task allowlist validation. An unauthenticated adjacent-network attacker can supply a task name and cause turbo-graph to execute tasks defined in the victim’s turbo.json, potentially enabling arbitrary code execution, sensitive data exposure, file modification, deployment actions, or destructive operations with the privileges of the developer’s OS account.
We recommend you to update turbo-graph to version 2.8.12.[/subscribe_to_unlock_form]
CVE-2026-59160 (CVSS 8.8 – High): A missing authentication vulnerability (CWE-306) exists in the /api/run endpoint. The embedded Next.js server listens on all network interfaces by default, while the endpoint performs no authentication, authorization, CSRF protection, or task allowlist validation. An unauthenticated adjacent-network attacker can supply a task name and cause turbo-graph to execute tasks defined in the victim’s turbo.json, potentially enabling arbitrary code execution, sensitive data exposure, file modification, deployment actions, or destructive operations with the privileges of the developer’s OS account.
We recommend you to update turbo-graph to version 2.8.12.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]