PatchSiren

nhost CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM nhost CVE published 2026-07-21

CVE-2026-47671

CVE-2026-47671 is a vulnerability in Nhost CLI versions prior to 1.46.0. The hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. This allows any process that can reach the developer's localhost service to query the configserver for local Nhost configuration and secrets, and mutate the local `.secrets` file. The vulnerabilit [truncated]