PT-2026-61516 · Unknown · Meshtastic
CVE-2026-44359
·
Published
2026-07-19
·
Updated
2026-07-24
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Meshtastic versions prior to 2.7.21.1370b23
Description
An insecure CI/CD workflow configuration in the
main matrix.yml workflow allows arbitrary code execution. The workflow is triggered by pull request target and executes code from an attacker-controlled fork without an approval gate. This occurs when pull requests are submitted by external users with author association: NONE. Because the check, build, and build-debian-src jobs execute this untrusted code with access to repository secrets and elevated GITHUB TOKEN permissions, an attacker can exfiltrate secrets, compromise self-hosted runners, or take over the repository. This flaw could lead to a supply chain compromise through the injection of malicious build artifacts.Recommendations
Update to version 2.7.21.1370b23.
As a temporary mitigation, disable the
main matrix.yml workflow or restrict pull request access.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Meshtastic