Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hcf7-66rw-9f5r | Turbo: Login callback CSRF/session fixation |
Tue, 19 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vercel:turborepo:*:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vercel
Vercel turborepo |
|
| Vendors & Products |
Vercel
Vercel turborepo |
Fri, 15 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local callback server with an attacker-controlled token. If accepted before the legitimate callback, the CLI could complete login with the wrong credentials. This affects users authenticating the turbo CLI against self-hosted remote cache/auth endpoints. Vercel-hosted login flows using device authorization are not affected. This vulnerability is fixed in 2.9.14. | |
| Title | Turborepo: Login callback CSRF/session fixation | |
| Weaknesses | CWE-352 CWE-384 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-15T16:45:06.076Z
Reserved: 2026-05-13T07:45:21.251Z
Link: CVE-2026-45773
Updated: 2026-05-15T16:45:00.876Z
Status : Analyzed
Published: 2026-05-15T16:16:15.137
Modified: 2026-06-17T10:52:32.470
Link: CVE-2026-45773
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:01:33Z
Github GHSA