CVE-2026-34200 Details
Description
Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on a network port, applies no inbound authentication and does not enforce strict CORS. This allows a malicious website visited on the same machine to issue cross-origin requests to the MCP server and invoke privileged tools using the developer's locally configured credentials. This vulnerability requires two explicit, non-default configuration steps to be exploitable. The default nhost mcp start configuration is not affected. This issue has been patched in version 1.41.0.
A vulnerability exists in the Nhost CLI MCP server in versions prior to 1.41.0, when explicitly configured to listen on a network port. The server fails to apply inbound authentication and does not enforce strict Cross-Origin Resource Sharing (CORS) policies. This allows a malicious website, accessed from the same machine, to send cross-origin requests to the MCP server and use privileged tools with the developer's local credentials. The vulnerability requires two specific configuration steps to be exploitable, and the default MCP server configuration is not affected.
Update to Nhost CLI version 1.41.0 or later, which removes the option to bind the MCP server to a network port.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nhost/nhost/security/advisories/GHSA-6c5x-3h35-vvw2 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/nhost/nhost/commit/15eae9285f9dce63e184b9bb24616474ffa5ccc9 | [email protected] | Patch |
| https://github.com/nhost/nhost/pull/4060 | [email protected] | Issue TrackingPatch |
| https://github.com/nhost/nhost/security/advisories/GHSA-6c5x-3h35-vvw2 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-942 | Permissive Cross-domain Policy with Untrusted Domains | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nhost cli | < 1.41.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | [email protected] |
| Mar 31, 2026 | CVE Modified | CISA-ADP |