THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g2r8-wvmj-jf5w (medium) — `nx graph` dev server permissive CORS policy

[GHSA] GHSA-g2r8-wvmj-jf5w (medium) — `nx graph` dev server permissive CORS policy

highgithub_advisoriesPublished 2026-07-31

GHSA-g2r8-wvmj-jf5w Severity: medium CVE: CVE-2026-54753

`nx graph` dev server permissive CORS policy

## Summary

The local HTTP server started by `nx graph` sent `Access-Control-Allow-Origin: *` on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the `/help` endpoint, which runs a target's confi

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g2r8-wvmj-jf5w