
CVE-2026-34969 Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the… https://www.cve.org/CVERecord?id=CVE-2026-34969
Post summary
The post discloses a flaw in Nhost's OAuth callback handling that exposes refresh tokens, but it provides no PoC, exploit tool, or active exploitation evidence.
