PT-2026-99929 · Unknown · Network Ups Tools

·

CVE-2026-54160

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Network UPS Tools (affected versions not specified)
Description A GitHub Actions script used to prepare tarballs and update GitHub Checks statuses and PR comments was mis-structured. The script mixed code running with higher privileges, specifically a single-use token with write permissions, and untrusted inputs from the PR source branch. This flaw allows a malicious pull request from a fork to extract the GITHUB TOKEN value. While the token is valid during the GitHub Actions job execution, it could be used to manipulate Git repository contents, commit checks, statuses, or issue and PR comments based on the assigned permissions.
Recommendations Apply the fixes implemented in commits 658b24e and 1aa31d1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54160
GHSA-W6WJ-3R73-FXMH

Affected Products

Network Ups Tools