PT-2026-103502 · Unknown+1 · Taskcluster+1

·

CVE-2026-55094

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Taskcluster versions prior to 100.3.0
Description Taskcluster, a task execution framework used for continuous integration and release processes, contains a flaw allowing unauthenticated remote code execution (RCE). This occurs on deployments where an anonymous role exposes the GraphQL endpoint and filter arguments are parsed using the sift library.
Recommendations Update to version 100.3.0.

Exploit

Fix

Code Injection

Missing Authentication

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-55094
GHSA-CCV5-C45X-2Q38

Affected Products

Taskcluster
Sift