PT-2026-61516 · Unknown · Meshtastic

CVE-2026-44359

·

Published

2026-07-19

·

Updated

2026-07-20

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Meshtastic versions prior to 2.7.21.1370b23
Description The main matrix.yml workflow in the GitHub repository is triggered by pull request target, allowing multiple jobs to check out and execute code from an attacker's fork. This process occurs without an approval gate, meaning pull requests from external users with author association: "NONE" trigger the CI workflow automatically. The workflow executes attacker-controlled files, granting access to repository secrets and elevated GITHUB TOKEN permissions. This flaw could lead to a supply chain compromise, self-hosted runner compromise, or a complete repository takeover.
Recommendations Update to version 2.7.21.1370b23. As a temporary mitigation, disable the main matrix.yml workflow or restrict pull request access.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44359
GHSA-6MWM-V2VV-PP96
GHSA-MJX5-98JQ-Q736

Affected Products

Meshtastic