Vulnerability in Turso CLI Affects User Authentication Credentials
CVE-2026-48790
5.5MEDIUM
What is CVE-2026-48790?
The Turso CLI, utilized for accessing the Turso database, contains a security vulnerability due to its improper handling of user JWTs. In versions prior to 1.0.26, the CLI saves the JWT to a file named settings.json with default permissions that allow it to be read by all users on the system. This exposure can lead to inappropriate access to the Turso platform, enabling unauthorized users to leverage the credentials stored within the readable file. Users are strongly advised to upgrade to version 1.0.26 or later to mitigate this risk.
Affected Version(s)
turso-cli < 1.0.26
