Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-44359

Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
Back to all
CVE

CVE-2026-44359

Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's mainmatrix.yml workflow is triggered by pullrequesttarget  and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUBTOKEN permissions. No approval gate exists. Pull requests from external users with authorassociation: "NONE" triggered the CI workflow automatically. The workflow directly executes attacker-controlled files from the fork checkout. This issue could have resulted in supply chain compromise, self-hosted runner compromise, and/or repository takeover for the repo. This issue is separate from GHSA-6mwm-v2vv-pp96, which addressed a command injection via github.headref in the setup job of the same workflow. That fix correctly moved to environment variables. However, the more critical fork checkout vulnerability across the check, build, and build-debian-src jobs was not addressed. Version 2.7.21.1370b23 contains a patch for thie issue.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
10
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
C
H
U
-

Related Resources

No items found.

References

https://drive.google.com/file/d/1GdHT2s5hMYCiHt4zrWt1q58mvL7WQC0M/view?usp=sharing, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44359.json, https://github.com/meshtastic/firmware/security/advisories/GHSA-6mwm-v2vv-pp96, https://github.com/meshtastic/firmware/security/advisories/GHSA-mjx5-98jq-q736, https://nvd.nist.gov/vuln/detail/CVE-2026-44359, https://github.com/meshtastic/firmware/commit/5716aeba3bc1e1d34fba9567ff88917ede4a78a5

Severity

10

CVSS Score
0
10

Basic Information

Base CVSS
10
EPSS Probability
0.01799%
EPSS Percentile
0.76693%
Introduced Version
0
Fix Available
5716aeba3bc1e1d34fba9567ff88917ede4a78a5

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading