VYPR

Yeger

by Deryeger

CVEs (1)

  • CVE-2026-59160higSep 9, 2026
    risk 0.45cvss epss

    ## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Summary `@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run`…