{"id":"CVE-2026-45773","aliases":["GHSA-hcf7-66rw-9f5r"],"url":"https://o3.security/vulnerability/CVE-2026-45773","summary":"Turborepo: Login callback CSRF/session fixation","details":"Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local callback server with an attacker-controlled token. If accepted before the legitimate callback, the CLI could complete login with the wrong credentials. This affects users authenticating the turbo CLI against self-hosted remote cache/auth endpoints. Vercel-hosted login flows using device authorization are not affected. This vulnerability is fixed in 2.9.14.","published":"2026-05-15T15:51:38.066Z","modified":"2026-08-12T03:51:22.866735611Z","cvss":null,"epss":{"score":0.00124,"percentile":0.02573,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"turbo","fixedVersion":"2.9.14"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45773.json"},{"type":"ADVISORY","url":"https://github.com/vercel/turborepo/security/advisories/GHSA-hcf7-66rw-9f5r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45773"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.866735611Z"}}