PT-2026-61516 · Unknown · Meshtastic

CVE-2026-44359

·

Published

2026-07-19

·

Updated

2026-07-24

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Meshtastic versions prior to 2.7.21.1370b23
Description An insecure CI/CD workflow configuration in the main matrix.yml workflow allows arbitrary code execution. The workflow is triggered by pull request target and executes code from an attacker-controlled fork without an approval gate. This occurs when pull requests are submitted by external users with author association: NONE. Because the check, build, and build-debian-src jobs execute this untrusted code with access to repository secrets and elevated GITHUB TOKEN permissions, an attacker can exfiltrate secrets, compromise self-hosted runners, or take over the repository. This flaw could lead to a supply chain compromise through the injection of malicious build artifacts.
Recommendations Update to version 2.7.21.1370b23. As a temporary mitigation, disable the main matrix.yml workflow or restrict pull request access.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44359
GHSA-6MWM-V2VV-PP96
GHSA-MJX5-98JQ-Q736

Affected Products

Meshtastic