CVE-2026-47671
Description
Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden nhost configserver used by nhost dev exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environment, any process that can reach the developer's localhost service, including a web page loaded from an arbitrary origin, can query the configserver for local Nhost configuration and secrets and can mutate the local .secrets file. This impacts developers using nhost dev: project admin secrets, JWT signing keys, webhook secrets, Grafana credentials, and custom environment variables can be read, and attacker-controlled secrets can be written to the local development project. Version 1.46.0 of Nhost CLI contains a fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/nhost/nhostGo | < 0.0.0-20260518172022-e407511627d2 | 0.0.0-20260518172022-e407511627d2 |
Affected products
3- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
5- github.com/nhost/nhost/commit/e407511627d2c2c1137a70e9ca1ca31095d23479nvdPatchWEB
- github.com/nhost/nhost/pull/4302nvdIssue TrackingPatchWEB
- github.com/nhost/nhost/security/advisories/GHSA-64cj-qvx5-m4f3nvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-64cj-qvx5-m4f3ghsaADVISORY
- github.com/nhost/nhost/releases/tag/[email protected]nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.