turso-cli persists Turso platform JWT with world-readable (0o644) file permissions
Summary
| CVE | CVE-2026-48790 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-11 18:17:34 UTC |
| Updated | 2026-08-12 23:17:21 UTC |
| Description | Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any other local UID on the host can read the file and recover the platform JWT, which grants full Turso platform access scoped to the user's organizations. Version 1.0.26 patches the issue. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.001050000 probability, percentile 0.012260000 (date 2026-08-14)
Problem Types: CWE-276 | CWE-732 | CWE-276 CWE-276: Incorrect Default Permissions | CWE-732 CWE-732: Incorrect Permission Assignment for Critical Resource
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Tursodatabase | Turso-cli | affected < 1.0.26 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/tursodatabase/turso-cli/security/advisories/GHSA-57f6-pvx8-hwj6 | [email protected] | github.com | |
| github.com/tursodatabase/turso-cli/commit/ffb914849216ef5a86353b3fa6cee6... | [email protected] | github.com | |
| github.com/spf13/viper/blob/v1.21.0/viper.go | [email protected] | github.com | |
| github.com/spf13/viper/blob/v1.21.0/viper.go | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.