Description
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The handler accepts the tasks, filter, and force query parameters, and buildResponseFromArgs passes attacker-selected task names to spawn() as Turbo CLI arguments. An adjacent-network attacker can execute any task defined in the victim repository's turbo.json with the privileges of the developer OS user, potentially exposing secrets, modifying files or infrastructure, or causing destructive availability effects. The use of an argument array prevents traditional shell metacharacter injection but does not prevent unauthorized execution of defined tasks. This issue is fixed in version 2.8.9.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via unauthenticated API
Action: Immediate Patch
AI Analysis

Impact

Yeger’s turbo‑graph component starts a Next.js server that binds to all network interfaces, including 0.0.0.0:29312, and exposes the /api/run endpoint over HTTP GET without authentication, authorization, CSRF protection, or a task allowlist. The endpoint accepts query parameters that are translated into Turbo CLI arguments and passed to spawn() as an array, preventing traditional shell injection but allowing any attacker to trigger the execution of any task declared in the victim’s turbo.json file. The attacker runs with the developer OS user’s privileges, potentially exposing secrets, modifying source files or infrastructure, or causing destructive availability effects.

Affected Systems

All releases of DerYeger:yeger before version 2.8.9 are affected, as the flaw resides in the turbo‑graph package (published under the @yeger/turbo‑graph scope). The vulnerable Next.js server listens on 0.0.0.0:29312, meaning any host that can reach that port on the target machine—such as an adjacent network—has access to the API.

Risk and Exploitability

This vulnerability carries a CVSS score of 8.8, indicating high severity, and an EPSS score of < 1%, indicating a very low but non‑zero exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires simply network proximity to the host running the server; no authentication or privilege escalation is needed beyond the developer OS user level inherent in the service. An attacker who knows the turbo.json configuration can execute arbitrary tasks, thus compromising confidentiality, integrity, or availability of the target system.

Generated by OpenCVE AI on September 20, 2026 at 15:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Yeger to version 2.8.9 or later, where the /api/run endpoint has been removed and authentication is enforced.
  • Configure firewall rules or network segmentation to restrict external access to port 29312, limiting exposure to trusted internal hosts.
  • Review the turbo.json configuration and remove or restrict any tasks that could expose sensitive data or perform destructive actions; ensure file and permission controls mitigate potential impact.

Generated by OpenCVE AI on September 20, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2r5q-h53f-9rp3 @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Deryeger
Deryeger yeger
Vendors & Products Deryeger
Deryeger yeger

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The handler accepts the tasks, filter, and force query parameters, and buildResponseFromArgs passes attacker-selected task names to spawn() as Turbo CLI arguments. An adjacent-network attacker can execute any task defined in the victim repository's turbo.json with the privileges of the developer OS user, potentially exposing secrets, modifying files or infrastructure, or causing destructive availability effects. The use of an argument array prevents traditional shell metacharacter injection but does not prevent unauthorized execution of defined tasks. This issue is fixed in version 2.8.9.
Title Yeger: Unauthenticated Network-Exposed Turborepo Task Execution via /api/run
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T17:29:33.831Z

Reserved: 2026-07-02T16:50:27.887Z

Link: CVE-2026-59160

cve-icon Vulnrichment

Updated: 2026-09-15T17:29:30.419Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:23.410

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-59160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function