PT-2026-61516 · Unknown · Meshtastic
CVE-2026-44359
·
Published
2026-07-19
·
Updated
2026-07-20
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Meshtastic versions prior to 2.7.21.1370b23
Description
The
main matrix.yml workflow in the GitHub repository is triggered by pull request target, allowing multiple jobs to check out and execute code from an attacker's fork. This process occurs without an approval gate, meaning pull requests from external users with author association: "NONE" trigger the CI workflow automatically. The workflow executes attacker-controlled files, granting access to repository secrets and elevated GITHUB TOKEN permissions. This flaw could lead to a supply chain compromise, self-hosted runner compromise, or a complete repository takeover.Recommendations
Update to version 2.7.21.1370b23.
As a temporary mitigation, disable the
main matrix.yml workflow or restrict pull request access.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Meshtastic