CVE-2026-47671
Published:July 21, 2026
Updated:July 21, 2026
Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden "nhost configserver" used by "nhost dev" exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environment, any process that can reach the developer's localhost service, including a web page loaded from an arbitrary origin, can query the configserver for local Nhost configuration and secrets and can mutate the local ".secrets" file. This impacts developers using "nhost dev": project admin secrets, JWT signing keys, webhook secrets, Grafana credentials, and custom environment variables can be read, and attacker-controlled secrets can be written to the local development project. Version 1.46.0 of Nhost CLI contains a fix.
Affected Packages
https://github.com/nhost/nhost.git (GITHUB):
Affected version(s) >=cli@1.32.0 <cli@1.46.0Fix Suggestion:
Update to version cli@1.46.0github.com/nhost/nhost (GO):
Affected version(s) >=v0.0.0-20241205151838-3b37af06a03d <v0.0.0-20260519092544-6632fadda56aFix Suggestion:
Update to version v0.0.0-20260519092544-6632fadda56aRelated Resources (5)
Do you need more information?
Contact UsCVSS v4
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.4
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE
Weakness Type (CWE)
Missing Authentication for Critical Function
EPSS
Base Score:
0.03