Skip to content
Noroxi

nhost records

5 published records for vendor nhost.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

5 records
  • Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass

    CriticalCVSS 9.3No exploitEPSS 1%

    nhost · nhost\/authMay 8, 2026

  • Nhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Port

    HighCVSS 7.7Proof of conceptEPSS 1%

    nhost · cliMar 31, 2026

  • Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets

    MediumCVSS 5.4No exploitEPSS 0%

    nhost · cliJul 21, 2026

  • Nhost Leaks the Refresh Token via URL Query Parameter in OAuth Provider Callback

    LowCVSS 2.3No exploitEPSS 0%

    nhost · nhost\/authApr 6, 2026

  • Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload

    LowCVSS 2.1No exploitEPSS 0%

    nhost · storageMar 20, 2026