PT-2026-99929 · Unknown · Network Ups Tools
CVSS v3.1
8.2
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Network UPS Tools (affected versions not specified)
Description
A GitHub Actions script used to prepare tarballs and update GitHub Checks statuses and PR comments was mis-structured. The script mixed code running with higher privileges, specifically a single-use token with write permissions, and untrusted inputs from the PR source branch. This flaw allows a malicious pull request from a fork to extract the
GITHUB TOKEN value. While the token is valid during the GitHub Actions job execution, it could be used to manipulate Git repository contents, commit checks, statuses, or issue and PR comments based on the assigned permissions.Recommendations
Apply the fixes implemented in commits 658b24e and 1aa31d1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Network Ups Tools