THREAT OPS › Threat News › [GHSA] GHSA-g2r8-wvmj-jf5w (medium) — `nx graph` dev server permissive CORS policy
[GHSA] GHSA-g2r8-wvmj-jf5w (medium) — `nx graph` dev server permissive CORS policy
GHSA-g2r8-wvmj-jf5w Severity: medium CVE: CVE-2026-54753
`nx graph` dev server permissive CORS policy
## Summary
The local HTTP server started by `nx graph` sent `Access-Control-Allow-Origin: *` on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the `/help` endpoint, which runs a target's confi
MITRE ATT&CK techniques
- Malicious PackageAML.T0011.001
Indicators of compromise
- CVE-2026-54753cve
- http://127.0.0.1:4211`url
Original source: https://github.com/advisories/GHSA-g2r8-wvmj-jf5w