Impact
Yeger’s turbo‑graph component starts a Next.js server that binds to all network interfaces, including 0.0.0.0:29312, and exposes the /api/run endpoint over HTTP GET without authentication, authorization, CSRF protection, or a task allowlist. The endpoint accepts query parameters that are translated into Turbo CLI arguments and passed to spawn() as an array, preventing traditional shell injection but allowing any attacker to trigger the execution of any task declared in the victim’s turbo.json file. The attacker runs with the developer OS user’s privileges, potentially exposing secrets, modifying source files or infrastructure, or causing destructive availability effects.
Affected Systems
All releases of DerYeger:yeger before version 2.8.9 are affected, as the flaw resides in the turbo‑graph package (published under the @yeger/turbo‑graph scope). The vulnerable Next.js server listens on 0.0.0.0:29312, meaning any host that can reach that port on the target machine—such as an adjacent network—has access to the API.
Risk and Exploitability
This vulnerability carries a CVSS score of 8.8, indicating high severity, and an EPSS score of < 1%, indicating a very low but non‑zero exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires simply network proximity to the host running the server; no authentication or privilege escalation is needed beyond the developer OS user level inherent in the service. An attacker who knows the turbo.json configuration can execute arbitrary tasks, thus compromising confidentiality, integrity, or availability of the target system.
OpenCVE Enrichment
Github GHSA