CVE-2026-59160 | yeger turbo-graph 2.8.8 API Run Endpoint route.ts GET tasks missing authentication

SecurityVulns

A vulnerability marked as critical has been reported in yeger turbo-graph 2.8.8. Impacted is the function GET of the file packages/turbo-graph-ui/app/api/run/route.ts of the component API Run Endpoint. This manipulation of the argument tasks causes missing authentication.

This vulnerability appears as CVE-2026-59160. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More