Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R U L L N 5.4 .0027 18.9 —
AFFECTED
Product Versions Fixed
cli < 1.46.0 – —
TIMELINE
May 19 Reserved by GitHub_M
Jul 21 EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added.
Jul 21 Published (CNA: GitHub_M)
Jul 30 EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added.
Description
Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environment, any process that can reach the developer's localhost service, including a web page loaded from an arbitrary origin, can query the configserver for local Nhost configuration and secrets and can mutate the local `.secrets` file. This impacts developers using `nhost dev`: project admin secrets, JWT signing keys, webhook secrets, Grafana credentials, and custom environment variables can be read, and attacker-controlled secrets can be written to the local development project. Version 1.46.0 of Nhost CLI contains a fix.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| May 19, 2026 | Reserved | Reserved by GitHub_M |
| July 21, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added. |
| July 21, 2026 | Published | Published (CNA: GitHub_M) |
| July 30, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| nhost | cli | — | < 1.46.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-47671 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.