PatchSiren

tursodatabase CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM tursodatabase CVE published 2026-08-11

CVE-2026-48790

CVE-2026-48790 is a vulnerability in Turso CLI, a command-line interface for the open-source database Turso. The vulnerability arises from the insecure persistence of Turso platform JWT credentials in a world-readable file, `settings.json`, on Linux and macOS systems. This issue allows any local user to read the file and gain full access to the Turso platform scoped to the user's organizations. The vulner [truncated]