Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-47671 — cli

🟡 CVSS 5.4 — Medium ⚠️ Exploit Public CWE-306 NVD
5.4
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets

Summary

The hidden nhost configserver used by nhost dev exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environment, any process that can reach the developer's localhost service, including a web page loaded from an arbitrary origin, can query the configserver for local Nhost configuration and secrets and can mutate the local .secrets file.

This impacts developers using nhost dev: project admin secrets, JWT signing keys, webhook secrets, Grafana credentials, and custom environment variables can be read, and attacker-controlled secrets can be written to the local development project.

Details

The CLI registers a hidden configserver command in cli/main.go:39 and cli/main.go:41. That command is used as the local development configserver image in nhost dev: cli/cmd/dev/up.go:176 through cli/cmd/dev/up.go:200 select nhost/cli:<version> as the configserver image, and cli/dockercompose/configserver.go:80 through cli/dockercompose/configserver.go:84 run it with the configserver command. The generated development dashboard receives the configserver and logs GraphQL URLs in public client-side environment variables at cli/dockercompose/compose.go:347 through cli/dockercompose/compose.go:358.

The configserver intentionally loads the local project files into Mimir's GraphQL resolver in cli/cmd/configserver/configserver.go:143 through cli/cmd/configserver/configserver.go:156. However, the authorization directives passed to graph.SetupRouter are no-ops:

  • cli/cmd/configserver/configserver.go:83 through cli/cmd/configserver/configserver.go:89 define dummyMiddleware, which calls the next resolver without checking app visibility.
  • cli/cmd/configserver/configserver.go:91 through cli/cmd/configserver/configserver.go:98 define dummyMiddleware2, which calls the next resolver without checking roles.
  • cli/cmd/configserver/configserver.go:161 through cli/cmd/configserver/configserver.go:170 pass those dummy directive handlers and cors.Default() to the GraphQL router.

The default rs/cors configuration allows all origins when no AllowedOrigins are specified: vendor/github.com/rs/cors/cors.go:163 through vendor/github.com/rs/cors/cors.go:167, and vendor/github.com/rs/cors/cors.go:248 through vendor/github.com/rs/cors/cors.go:249 show Default() uses Options{}. A browser preflight from an arbitrary origin receives Access-Control-Allow-Origin: *.

The exposed GraphQL schema includes sensitive queries and mutations:

  • vendor/github.com/nhost/be/services/mimir/schema/schema.graphqls:41 through vendor/github.com/nhost/be/services/mimir/schema/schema.graphqls:57 expose configRawJSON, config, and appSecrets by app ID. appSecrets is protected only by @hasAppVisibility, which the configserver replaces with the no-op dummyMiddleware.
  • vendor/github.com/nhost/be/services/mimir/schema/schema.graphqls:117 through vendor/github.com/nhost/be/services/mimir/schema/schema.graphqls:128 expose insertSecret, updateSecret, and deleteSecret, also protected only by the no-op @hasAppVisibility directive.
  • vendor/github.com/nhost/be/services/mimir/graph/q_app_secrets.go:10 through vendor/github.com/nhost/be/services/mimir/graph/q_app_secrets.go:30 return the app's secrets.
  • vendor/github.com/nhost/be/services/mimir/graph/q_config_raw_json.go:12 returns raw JSON for the app configuration, which includes sensitive fields such as Hasura admin secrets and JWT signing keys in local development config.
  • vendor/github.com/nhost/be/services/mimir/graph/m_insert_secret.go:11 through vendor/github.com/nhost/be/services/mimir/graph/m_insert_secret.go:47 append attacker-supplied secrets and call plugin UpdateSecrets.
  • cli/cmd/configserver/local.go:164 through cli/cmd/configserver/local.go:175 marshal the new secrets and write them to the configured local secrets file with os.WriteFile.

Because the local configserver uses a fixed zero UUID app ID for the local app (cli/cmd/configserver/local.go:134) and does not require cookies, tokens, or admin headers, a request only needs the known GraphQL endpoint and app ID.

Candidate score: 14/14.

  • Reachability: 2 — reachable in the documented local development path using nhost dev and directly through the hidden configserver command.
  • Attacker control: 2 — GraphQL query and mutation bodies are fully attacker-controlled.
  • Privilege required: 2 — no authentication or local Nhost privileges are required beyond network/browser reachability to the developer's local configserver.
  • Sink impact: 2 — sensitive secret read and local secrets file write.
  • Mitigation weakness: 2 — role/app-visibility directives are replaced with no-op handlers, and CORS permits all origins.
  • D

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality low, integrity low, availability none.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: Required — someone has to click, open or visit something.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: Low — limited, and the attacker does not choose what is affected.
  • Integrity impact: Low — limited, and the attacker does not choose what is affected.
  • Availability impact: None.

Weakness class

CVE-2026-47671 is classified as CWE-306: Missing Authentication for Critical Function. A sensitive function can be reached without authenticating at all.

Affected software

CVE-2026-47671 is recorded against 2 packages.

  • cli (fixed in 1.46.0)
  • github.com/nhost/nhost

Timeline and source

Published on 21 July 2026 and last revised on 30 July 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com
github.com
github.com
github.com
github.com

Other advisories for this package

cli has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-306: Missing Authentication for Critical Function) in other software:

Details

Severity MEDIUM
CVSS Score 5.4
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CWE CWE-306
Public Exploit ⚠️ Yes
Source NVD
Published 2026-07-21
Updated 2026-08-20
Modified 2026-07-30

Affected Packages

Software From version Fixed in
cli 1.46.0
github.com/nhost/nhost

Exploit Protection

Are you running cli?

CVE-2026-47671 carries CVSS 5.4 Medium rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-47671 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026