Vulnerability in Turso CLI Affects User Authentication Credentials
CVE-2026-48790

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-48790?

The Turso CLI, utilized for accessing the Turso database, contains a security vulnerability due to its improper handling of user JWTs. In versions prior to 1.0.26, the CLI saves the JWT to a file named settings.json with default permissions that allow it to be read by all users on the system. This exposure can lead to inappropriate access to the Turso platform, enabling unauthorized users to leverage the credentials stored within the readable file. Users are strongly advised to upgrade to version 1.0.26 or later to mitigate this risk.

Affected Version(s)

turso-cli < 1.0.26

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.