Nhost, an open-source Firebase alternative featuring GraphQL capabilities, contains a critical authentication vulnerability affecting versions prior to 0.48.0. The OAuth provider callback flow exposes refresh tokens directly in redirect URL query parameters, creating multiple exposure vectors through browser history, server access logs, HTTP Referer headers, and proxy/CDN logs. Although refresh tokens are single-use, the exposure creates significant confidentiality risks across infrastructure and integrated services under developer control. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction, indicating broad exploitability. The attack has low complexity and results in high confidentiality impact with no integrity or availability concerns. The FAUCET Risk Score of 48.0/100 reflects elevated risk within the vulnerability landscape. The vulnerability shows no evidence of active exploitation and does not appear on the KEV catalog, suggesting limited real-world weaponization at present. However, its presence on the Active Hot List indicates ongoing community attention and monitoring. A patch is available in version 0.48.0, and organizations running vulnerable versions should prioritize upgrading immediately given the straightforward nature of token exposure through standard logging mechanisms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.48.0CPE matchmatch criteria | cpe:2.3:a:nhost:nhost\/auth:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.